CWE-90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

56 vulnerabilities with CWE-90
CVE-2024-54852 CRITICAL
Sismics Teedy < 1.12 - LDAP Injection
CVSS 9.8
CVE-2024-56841 HIGH
Mendix LDAP <V1.1.2 - LDAP Injection
CVSS 7.4
CVE-2024-27310 MEDIUM
Zoho ManageEngine ASDSelfService Plus <6401 - DoS
CVSS 5.3
CVE-2024-33868 CRITICAL
Linqi < 1.4.0.1 - LDAP Injection
CVSS 9.8
CVE-2023-51446 MEDIUM
GLPI <10.0.12 - LDAP Injection
CVSS 5.9
CVE-2023-31025 MEDIUM
NVIDIA DGX A100 BMC - Info Disclosure
CVSS 6.5
CVE-2023-29050 HIGH
LDAP contacts provider - Info Disclosure
CVSS 7.6
CVE-2023-6905 MEDIUM
Nxfilter - LDAP Injection
CVSS 4.3
CVE-2023-3447 HIGH
WordPress <4.1.5 - LDAP Injection
CVSS 7.6
CVE-2023-28853 HIGH
Mastodon <3.5.8, <4.0.4, <4.1.2 - SQL Injection
CVSS 7.7
CVE-2022-4254 HIGH
Fedoraproject Sssd < 2.3.1 - LDAP Injection
CVSS 8.8
CVE-2022-45910 MEDIUM
Apache Manifoldcf < 2.23 - Injection
CVSS 5.3
CVE-2021-43782 MEDIUM
Tuleap - Privilege Escalation
CVSS 6.7
CVE-2021-41276 MEDIUM
Tuleap - Privilege Escalation
CVSS 6.7
CVE-2021-43350 CRITICAL
Apache Traffic Control - Info Disclosure
CVSS 9.8
CVE-2021-41232 HIGH
Thunderdome <1.16.3 - Command Injection
CVSS 8.1
CVE-2021-32651 LOW
OneDev <4.4.1 - Blind LDAP Injection
CVSS 3.1
CVE-2020-5246 HIGH
Traccar < 4.9 - Injection
CVSS 7.7
CVE-2020-5281 MEDIUM
Cesnet Perun < 3.9.1 - Incorrect Permission Assignment
CVSS 6.2
CVE-2019-11277 HIGH
Cloudfoundry Cf-deployment < 11.1.0 - Injection
CVSS 8.1
CVE-2019-4297 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 - Comman...
CVSS 5.4
CVE-2018-5730 LOW
MIT krb5 1.6+ - Privilege Escalation
CVSS 3.8
CVE-2017-4927 HIGH
VMware vCenter Server <6.5 U1, <6.0 U3c - DoS
CVSS 7.5
CVE-2017-14596 CRITICAL
Joomla! <3.8.0 - Info Disclosure
CVSS 9.8
CVE-2017-8790 CRITICAL
Accellion File Transfer Appliance < 9_12_40 - LDAP Injection
CVSS 9.8
Details
Vulnerabilities 56