Improper neutralization of special elements used in an LDAP query (LDAP injection) vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).
This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat AMQ Broker 7.12.7 | RedHat | bcprov-jdk18on | * |
| Red Hat AMQ Broker 7.13.5 | RedHat | bcprov-jdk18on | * |
| Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 | RedHat | bcprov-jdk18on | * |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | RedHat | bcprov-debug-jdk15on | * |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | RedHat | bcprov-jdk15on | * |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | RedHat | bcprov-jdk18on | * |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | RedHat | bcprov-lts8on | * |
| Red Hat build of Quarkus 3.20.6.SP1 | RedHat | bcprov-jdk18on | * |
| Red Hat build of Quarkus 3.27.3.SP1 | RedHat | bcprov-jdk18on | * |
| Red Hat JBoss Enterprise Application Platform 8.1 | RedHat | bcprov-ext-jdk15on | * |
| Red Hat JBoss Enterprise Application Platform 8.1 | RedHat | bcprov-ext-jdk18on | * |
| Red Hat JBoss Enterprise Application Platform 8.1 | RedHat | bcprov-jdk12 | * |
| Red Hat JBoss Enterprise Application Platform 8.1 | RedHat | bcprov-jdk15 | * |
| Red Hat JBoss Enterprise Application Platform 8.1 | RedHat | bcprov-jdk15on | * |
| Red Hat JBoss Enterprise Application Platform 8.1 | RedHat | bcprov-jdk15to18 | * |
| Red Hat JBoss Enterprise Application Platform 8.1 | RedHat | bcprov-jdk18on | * |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | RedHat | eap8-bouncycastle-0:1.84.0-1.redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | RedHat | eap8-bouncycastle-0:1.84.0-1.redhat_00001.1.el9eap | * |
| Red Hat OpenShift Dev Spaces 3.28 | RedHat | devspaces/openvsx-rhel9:1779528224 | * |
| Red Hat OpenShift Dev Spaces 3.28 | RedHat | devspaces/pluginregistry-rhel9:1779359423 | * |
| Bouncycastle | Ubuntu | esm-apps/xenial | * |