CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
56 vulnerabilities with CWE-90
CVE-2024-54852
CRITICAL
Sismics Teedy < 1.12 - LDAP Injection
CVSS 9.8
CVE-2024-56841
HIGH
Mendix LDAP <V1.1.2 - LDAP Injection
CVSS 7.4
CVE-2024-27310
MEDIUM
Zoho ManageEngine ASDSelfService Plus <6401 - DoS
CVSS 5.3
CVE-2024-33868
CRITICAL
Linqi < 1.4.0.1 - LDAP Injection
CVSS 9.8
CVE-2023-51446
MEDIUM
GLPI <10.0.12 - LDAP Injection
CVSS 5.9
CVE-2023-31025
MEDIUM
NVIDIA DGX A100 BMC - Info Disclosure
CVSS 6.5
CVE-2023-29050
HIGH
LDAP contacts provider - Info Disclosure
CVSS 7.6
CVE-2023-6905
MEDIUM
Nxfilter - LDAP Injection
CVSS 4.3
CVE-2023-3447
HIGH
WordPress <4.1.5 - LDAP Injection
CVSS 7.6
CVE-2023-28853
HIGH
Mastodon <3.5.8, <4.0.4, <4.1.2 - SQL Injection
CVSS 7.7
CVE-2022-4254
HIGH
Fedoraproject Sssd < 2.3.1 - LDAP Injection
CVSS 8.8
CVE-2022-45910
MEDIUM
Apache Manifoldcf < 2.23 - Injection
CVSS 5.3
CVE-2021-43782
MEDIUM
Tuleap - Privilege Escalation
CVSS 6.7
CVE-2021-41276
MEDIUM
Tuleap - Privilege Escalation
CVSS 6.7
CVE-2021-43350
CRITICAL
Apache Traffic Control - Info Disclosure
CVSS 9.8
CVE-2021-41232
HIGH
Thunderdome <1.16.3 - Command Injection
CVSS 8.1
CVE-2021-32651
LOW
OneDev <4.4.1 - Blind LDAP Injection
CVSS 3.1
CVE-2020-5246
HIGH
Traccar < 4.9 - Injection
CVSS 7.7
CVE-2020-5281
MEDIUM
Cesnet Perun < 3.9.1 - Incorrect Permission Assignment
CVSS 6.2
CVE-2019-11277
HIGH
Cloudfoundry Cf-deployment < 11.1.0 - Injection
CVSS 8.1
CVE-2019-4297
MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 - Comman...
CVSS 5.4
CVE-2018-5730
LOW
MIT krb5 1.6+ - Privilege Escalation
CVSS 3.8
CVE-2017-4927
HIGH
VMware vCenter Server <6.5 U1, <6.0 U3c - DoS
CVSS 7.5
CVE-2017-14596
CRITICAL
Joomla! <3.8.0 - Info Disclosure
CVSS 9.8
CVE-2017-8790
CRITICAL
Accellion File Transfer Appliance < 9_12_40 - LDAP Injection
CVSS 9.8
Details
Vulnerabilities
56