CVE-2022-29155
Description
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
18.85
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.4.49+dfsg-2ubuntu1.9_i386.deb | Linux |
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.4.49+dfsg-2ubuntu1.9_amd64.deb | Linux |
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.4.45+dfsg-1ubuntu1.11_i386.deb | Linux |
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.4.45+dfsg-1ubuntu1.11_amd64.deb | Linux |
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.5.6+dfsg-1~exp1ubuntu1.1_i386.deb | Linux |
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.5.6+dfsg-1~exp1ubuntu1.1_amd64.deb | Linux |
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.5.11+dfsg-1~exp1ubuntu3.1_i386.deb | Linux |
| Lightweight Directory Access Protocol (USN-5424-1) slapd_2.5.11+dfsg-1~exp1ubuntu3.1_amd64.deb | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) libldap-2_4-2-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) libldap-2_4-2-32bit-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) libldap-2_4-2-debuginfo-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) libldap-2_4-2-debuginfo-32bit-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-back-meta-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-back-meta-debuginfo-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-client-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-client-debuginfo-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-debuginfo-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-debugsource-2.4.41-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-doc-2.4.41-22.10.1.noarch.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-ppolicy-check-password-1.2-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2022:1771-1(SUSE Linux Enterprise Server 12-SP5 ) openldap2-ppolicy-check-password-debuginfo-1.2-22.10.1.x86_64.rpm | Linux |
| SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-1.8.0_sr8.15-30.117.1.x86_64.rpm | Linux |
| SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-alsa-1.8.0_sr8.15-30.117.1.x86_64.rpm | Linux |
| SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-devel-1.8.0_sr8.15-30.117.1.x86_64.rpm | Linux |
| SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-plugin-1.8.0_sr8.15-30.117.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) wayland-devel-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-egl1-99~1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-client0-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-cursor0-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-server0-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) wayland-debugsource-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) wayland-devel-debuginfo-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-client0-32bit-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-server0-32bit-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-egl1-debuginfo-99~1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-client0-debuginfo-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-cursor0-debuginfo-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-server0-debuginfo-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-client0-32bit-debuginfo-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| SUSE-SU-2023:1860-1(Basesystem Module 15-SP4 ) libwayland-server0-32bit-debuginfo-1.19.0-150400.3.3.1.x86_64.rpm | Linux |
| openldap security update(DSA-5140-1) libldap2-dev_2.4.57+dfsg-3+deb11u1_i386.deb | Linux |
| openldap security update(DSA-5140-1) libldap2-dev_2.4.57+dfsg-3+deb11u1_amd64.deb | Linux |
| openldap security update(DSA-5140-1) libldap2-dev_2.4.47+dfsg-3+deb10u7_i386.deb | Linux |
| openldap security update(DSA-5140-1) libldap2-dev_2.4.47+dfsg-3+deb10u7_amd64.deb | Linux |
| openldap security update(DSA-5140-1) libldap-common_2.4.57+dfsg-3+deb11u1_all.deb | Linux |
| openldap security update(DSA-5140-1) libldap-common_2.4.47+dfsg-3+deb10u7_all.deb | Linux |
| openldap security update(DSA-5140-1) libldap-2.4-2_2.4.57+dfsg-3+deb11u1_i386.deb | Linux |
| openldap security update(DSA-5140-1) libldap-2.4-2_2.4.57+dfsg-3+deb11u1_amd64.deb | Linux |
| openldap security update(DSA-5140-1) libldap-2.4-2_2.4.47+dfsg-3+deb10u7_i386.deb | Linux |
| openldap security update(DSA-5140-1) libldap-2.4-2_2.4.47+dfsg-3+deb10u7_amd64.deb | Linux |
| openldap security update(DSA-5140-1) ldap-utils_2.4.57+dfsg-3+deb11u1_i386.deb | Linux |
| openldap security update(DSA-5140-1) ldap-utils_2.4.57+dfsg-3+deb11u1_amd64.deb | Linux |
| openldap security update(DSA-5140-1) ldap-utils_2.4.47+dfsg-3+deb10u7_i386.deb | Linux |
| openldap security update(DSA-5140-1) ldap-utils_2.4.47+dfsg-3+deb10u7_amd64.deb | Linux |
| openldap security update(DSA-5140-1) slapi-dev_2.4.57+dfsg-3+deb11u1_i386.deb | Linux |
| openldap security update(DSA-5140-1) slapi-dev_2.4.57+dfsg-3+deb11u1_amd64.deb | Linux |
| openldap security update(DSA-5140-1) slapi-dev_2.4.47+dfsg-3+deb10u7_i386.deb | Linux |
| openldap security update(DSA-5140-1) slapi-dev_2.4.47+dfsg-3+deb10u7_amd64.deb | Linux |
| openldap security update(DSA-5140-1) slapd-smbk5pwd_2.4.57+dfsg-3+deb11u1_all.deb | Linux |
| openldap security update(DSA-5140-1) slapd-smbk5pwd_2.4.47+dfsg-3+deb10u7_all.deb | Linux |
| openldap security update(DSA-5140-1) slapd-contrib_2.4.57+dfsg-3+deb11u1_i386.deb | Linux |
| openldap security update(DSA-5140-1) slapd-contrib_2.4.57+dfsg-3+deb11u1_amd64.deb | Linux |
| openldap security update(DSA-5140-1) slapd-contrib_2.4.47+dfsg-3+deb10u7_i386.deb | Linux |
| openldap security update(DSA-5140-1) slapd-contrib_2.4.47+dfsg-3+deb10u7_amd64.deb | Linux |
| openldap security update(DSA-5140-1) slapd_2.4.57+dfsg-3+deb11u1_i386.deb | Linux |
| openldap security update(DSA-5140-1) slapd_2.4.57+dfsg-3+deb11u1_amd64.deb | Linux |
| openldap security update(DSA-5140-1) slapd_2.4.47+dfsg-3+deb10u7_i386.deb | Linux |
| openldap security update(DSA-5140-1) slapd_2.4.47+dfsg-3+deb10u7_amd64.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234