LDAP Account Manager (LAM) 7.9.1

CPE Details

LDAP Account Manager (LAM) 7.9.1
7.9.1
2022-04-25
12h48 +00:00
2022-07-30
01h52 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ldap-account-manager:ldap_account_manager:7.9.1:*:*:*:*:*:*:*

Informations

Vendor

ldap-account-manager

Product

ldap_account_manager

Version

7.9.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-31084 2022-06-27 18h55 +00:00 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes. An attacker can inject the first constructor argument. This can lead to code execution if non-LAM classes are instantiated that execute code during object creation. This issue has been fixed in version 8.0.
8.1
Haute
CVE-2022-31086 2022-06-27 18h50 +00:00 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue.
8.8
Haute
CVE-2022-31087 2022-06-27 18h50 +00:00 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An attacker capable of writing files under www-data privileges can write a web-shell into this directory, and gain a Code Execution on the host. This issue has been fixed in version 8.0. Users unable to upgrade should disallow executing PHP scripts in (/var/lib/ldap-account-manager/)tmp directory.
7.8
Haute
CVE-2022-31088 2022-06-27 18h45 +00:00 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0.
5.3
Moyen