Impact
The AD LDAP app for Splunk SOAR contains a flaw in versions earlier than 2.3.8 where Active Directory response data is written to a persistent debug log when an action is triggered. This exposes confidential information such as usernames, group memberships, and potentially passwords if they appear in the response. Based on the description, it is inferred that a user who can read the log file could obtain these sensitive details, but the CVE does not explicitly state that passwords are exposed, so that inference must be noted as derived from the available information.
Affected Systems
Splunk’s AD LDAP app for Splunk SOAR versions below 2.3.8 are affected. The fix requires the application to be updated to a version that is compatible with Splunk SOAR 8.6.0 or newer. Administrators should verify that their Splunk SOAR instance meets the minimum base version before installing the patched app.
Risk and Exploitability
The CVSS v3.1 base score of 4.3 indicates the vulnerability's severity but the CVE data does not assign a specific risk level. The EPSS score is not available, so no assessment of exploitation probability can be made from that metric. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely exploited yet. Insufficient data is available to confirm external exposure; the likely attack vector is inferred to be an authenticated internal user with permission to run actions, which is required to trigger the logging of sensitive data.
OpenCVE Enrichment