CVE-2023-23951
Published Jan 26, 2023Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
Vendor/product archive
3 CVEs tagged to broadcom / symantec_identity_manager — 0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.