CVE-2022-22360
CVE-2022-22360
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.5EPSS 1.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
19 jul 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782.
CVSS:3.0/PR:L/AV:N/UI:N/I:H/AC:H/A:H/S:U/C:H/RL:O/RC:C/E:U
Productos afectados
IBM · Sterling Partner Engagement ManagerIBM · Sterling Partner Engagement Manager on Cloud¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →