CVE-2022-31084

HIGH

LDAP Account Manager <8.0 - Code Injection

Title source: llm
STIX 2.1

Description

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes. An attacker can inject the first constructor argument. This can lead to code execution if non-LAM classes are instantiated that execute code during object creation. This issue has been fixed in version 8.0.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2022/dsa-5177
Exploit, Third Party Advisory x_refsource_misc
https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations/

Scores

CVSS v3 8.1
EPSS 0.0185
EPSS Percentile 76.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-88
Status published
Products (2)
debian/debian_linux 11.0
ldap-account-manager/ldap_account_manager < 8.0
Published Jun 27, 2022
Tracked Since Feb 18, 2026