LDAP injection in Apache Camel - CVE-2022-45046
Published: December 5, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper input validation when processing DLAP queries. A remote non-authenticated attacker can send a specially crafted LDAP query via the filter option to the application, bypass authentication process and gain unauthorized access to the application.
Affected software
IBM Data Risk Manager
How to mitigate CVE-2022-45046
IBM Data Risk Manager - update to 2.0.6.16