Executive brief
HAVELSAN Liman MYS, a centralized management system, is vulnerable to a security flaw that could allow an attacker to manipulate directory service queries. By exploiting this, an authorized user could potentially bypass security controls to access sensitive information, modify directory data, or disrupt authentication services. This poses a significant risk to the integrity of user identity management and overall system security.
Technical details
An LDAP injection vulnerability exists in HAVELSAN Liman MYS due to improper neutralization of special elements used in LDAP queries (CWE-90). The flaw allows a network-based attacker with low-level privileges to submit crafted input that alters the logic of LDAP queries executed by the application. Successful exploitation can lead to unauthorized information disclosure, modification of directory entries, or denial of service within the LDAP environment. The issue is addressed in version release.Master.1107 and later.
Affected products
- HAVELSAN Inc. Liman MYS before release.Master.1107
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory