Critical severity9.3NVD Advisory· Published Sep 19, 2022· Updated Jun 17, 2026
CVE-2022-0143
CVE-2022-0143
Description
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
Affected products
3cpe:2.3:a:forgerock:ldap_connector:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:forgerock:ldap_connector:*:*:*:*:*:*:*:*range: <1.5.20.9
- (no CPE)range: <1.5.20.9
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
2- backstage.forgerock.com/downloads/browse/idm/featured/connectorsnvdPatchVendor Advisory
- backstage.forgerock.com/knowledge/kb/article/a11380515nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.