Executive brief
NT-ware uniFLOW Universal Login Manager (ULM) Standalone, a tool used for managing user access to office printing devices, contains a security flaw. An authorized administrator could potentially view sensitive configuration details, such as credentials for email (SMTP) or directory services (LDAP), through the management interface. This issue only affects standalone installations and does not impact deployments connected to uniFLOW Server or uniFLOW Online.
Technical details
An information disclosure vulnerability (CWE-522) exists in NT-ware uniFLOW Universal Login Manager (ULM) Standalone versions 5.10 and earlier. The flaw resides in the Remote User Interface (RUI), where sensitive configuration data—specifically credentials or parameters related to SMTP and LDAP integrations—are insufficiently protected. An attacker must already possess high-level administrative privileges and have network access to the device's management interface to exploit this. Successful exploitation allows the administrator to retrieve credentials that should otherwise be masked or protected. This vulnerability does not affect ULM instances managed via uniFLOW Server or uniFLOW Online.
Affected products
- NT-ware uniFLOW Universal Login Manager (ULM) Standalone <= 5.10
Timeline
- 2026-07-06: advisory
- 2026-07-06: disclosed