A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to bypass username verification.
The vulnerability results from improper validation or lack of appropriate escaping of input data passed to LDAP queries (CWE-90). An attacker can craft malicious input containing special LDAP control characters that modify the logic of the directory query. This makes it possible to bypass the username verification mechanism without knowing valid credentials. The attack does not require prior authentication or user interaction.
An attacker can bypass user identity verification, which may lead to unauthorized access to resources protected by LDAP-based authentication mechanisms. This results in a violation of the confidentiality and integrity of data accessible after login.
The Mendix LDAP module should be updated to version V1.1.2 or newer. Detailed information is available in the Siemens ProductCERT bulletin at: https://cert-portal.siemens.com/productcert/html/ssa-314390.html
Mendix LDAP — all versions below V1.1.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X