LDAP injection in Apache Kerby - CVE-2023-25613
Published: February 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper input validation when processing DLAP queries in LdapIdentityBackend. A remote non-authenticated attacker can send a specially crafted LDAP query to the application, bypass authentication process and gain unauthorized access to the application.
Affected software
Oracle Communications Cloud Native Configuration Console
QRadar User Behavior Analytics
Cloudera Data Platform Private Cloud Base for IBM
How to mitigate CVE-2023-25613
QRadar User Behavior Analytics - update to 4.1.16
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2