· updated 2023-12-06

CVE-2023-32268: cleartext LDAP credentials in MicroFocus Filr Appliance

A Filr administrator can retrieve, in cleartext, the LDAP service password used to synchronise Active Directory, opening a path to full domain controller compromise.

CVE
CVE-2023-32268
Product
MicroFocus (OpenText) Filr Appliance 3.0 build 4670
CVSS
7.2
Severity
high
Status
patched

TL;DR

MicroFocus Filr Appliance 3.0 (build 4670) shows an administrator the service password used to synchronise users from Active Directory over LDAP. The password is masked in the interface, but it is returned in cleartext in the response of the RPC call that populates the configuration page. With that credential an attacker can authenticate to the domain controller and proceed with data exfiltration and lateral movement.

A vulnerability I found during a penetration test carried out in my work at Tinexta Cyber. Publication follows responsible disclosure: details are released only after the vendor’s patch.

Context

Filr is MicroFocus’s (now OpenText) product for file access and sharing from any device. In enterprise deployments it is integrated with Active Directory: a service account lets Filr synchronise domain users over LDAP.

The vulnerability surfaced during a penetration test on a client exposing Filr. Starting from administrative credentials of the product — i.e. an attacker or insider already holding privileged access to the application — it was possible to recover the password of the LDAP service account.

Details

Vulnerability CVSS v3.1 Vector
LDAP Credential Disclosure 7.2 (High) AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The web interface exposes, to a highly privileged user, the credentials of the service account used to synchronise Active Directory users over LDAP. In the console the password appears masked.

Administrative console page

LDAP configuration page with masked password

Proof of Concept

After logging in with administrative credentials you reach the web app configuration, including the LDAP section. The password is masked in the UI, but by intercepting the POST request to the gwtTeaming.rpc component it appears in cleartext in the response body.

HTTP request to the gwtTeaming.rpc component

HTTP response with the cleartext password

Impact

The LDAP synchronisation account typically holds elevated domain privileges. An attacker who obtains its password can attempt to access the domain controller with the highest privileges and, from there, exfiltrate sensitive data and deploy ransomware.

Fix and mitigations

The vendor released the patch on 19 May 2023: upgrade the appliance to the latest available version.

Timeline

Date Event
2023-01-30 Vulnerability discovered
2023-03-01 First contact with the vendor by e-mail
2023-03-07 Vendor forwards the report to the internal team
2023-04-19 Vendor confirms handling has started
2023-05-19 Patch released
2023-06-28 Security advisory published
2023-12-06 CVE-2023-32268 assigned

References

← all posts