cognitive cybersecurity intelligence

News and Analysis

Search

Apache Derby Vulnerability Let Attackers Bypass Authentication with LDAP Injection

A critical vulnerability (CVE-2022-46337) in Apache Derby allows authentication bypass via LDAP injection, rated 9.1 on the CVSS scale. Attackers can exploit this flaw to access or modify sensitive data, create databases, and execute malicious code. Affected versions include 10.1.1.0 to 10.16.1.1. Upgrade to Derby 10.17.1.0 for protection; IBM offers patches for its impacted products.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts