Generated remediation guidance and an executive summary. No account required.
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP OpenSSL extension is not installed or encryption is disabled by configuration. This issue has been fixed in version 8.0. Users unable to upgrade should install the PHP OpenSSL extension and make sure session encryption is enabled in LAM main configuration.
Cite this page
CVE-2022-31085. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-31085
Use CWE-311, Ldap-Account-Manager vendor hub and Ldap Account Manager product page to widen CVE-2022-31085 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-27894, CVE-2022-31086 and CVE-2018-8764 for nearby disclosures in the same product family.