Impact
The AD LDAP app for Splunk SOAR is vulnerable to a filter injection attack that allows a user with action execution permissions to inject crafted input into AD queries. Exploitation can result in enumeration of accounts, groups, and organizational units, reading sensitive attributes from arbitrary directory objects, and redirecting modification actions to unintended targets. This is a CWE‑90 vulnerability that undermines confidentiality and integrity of the directory.
Affected Systems
The vulnerability affects Splunk’s AD LDAP app for Splunk SOAR versions earlier than 2.3.8. Affected installations run on Splunk SOAR 8.6.0 or higher, since the fixed app version requires that base platform. Any deployment of the app under version 2.3.8 or lower should be considered at risk.
Risk and Exploitability
The CVSS base score is 5.4, indicating a moderate severity. EPSS is not reported and the vulnerability is not in the KEV catalog. Attackers need a role that permits running actions and network access to the Splunk SOAR management interface. The injection vector likely occurs through the action parameter interface that accepts user input for AD queries.
OpenCVE Enrichment