Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
The vulnerability results from improper neutralization of special characters used in LDAP queries (CWE-90). An attacker can inject maliciously crafted input data that modifies the logic of the LDAP query sent by the application. As a result, it is possible to bypass authentication mechanisms or gain access to data stored in the LDAP directory. The attack can be conducted remotely over the network without requiring any privileges.
An attacker can gain unauthorized access to sensitive data (confidentiality breach) and manipulate data in the LDAP directory or application logic (integrity breach).
Apache OFBiz should be updated to version 24.09.06 or newer, which contains a patch eliminating the described vulnerability.
Apache OFBiz in versions prior to 24.09.06
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache Ofbiz
APPApache< 24.09.06
Related vulnerabilities
Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację
Path Traversal w Apache OFBiz umożliwiający zdalne wykonanie kodu
Apache OFBiz — Auth Bypass i RCE poprzez błąd logiki zmiany hasła
Apache OFBiz — użycie zakodowanego na stałe klucza kryptograficznego
Apache OFBiz: Code Injection w pluginie scrum umożliwia RCE