CVE-2022-46337 | Apache Derby up to 10.16.1.1 Authenticator Username ldap injection (WID-SEC-2026-0783)
A vulnerability marked as problematic has been reported in Apache Derby up to 10.16.1.1. Affected by this vulnerability is an unknown functionality of the component Authenticator. The manipulation of the argument Username leads to ldap injection.
This vulnerability is referenced as CVE-2022-46337. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.