CVE-2024-25655

Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.
Configurations

No configuration.

History

No history.

Information

Published : 2024-03-18 20:15

Updated : 2024-11-21 09:01


NVD link : CVE-2024-25655

Mitre link : CVE-2024-25655

CVE.ORG link : CVE-2024-25655


JSON object : View

Products Affected

No product.

CWE
CWE-922

Insecure Storage of Sensitive Information