Lucene search

K
cveRedhatCVE-2022-1414
HistoryOct 19, 2022 - 6:15 p.m.

CVE-2022-1414

2022-10-1918:15:11
CWE-1173
CWE-20
redhat
web.nvd.nist.gov
36
10
3scale
api
management
input sanitation
security vulnerability
cve-2022-1414
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

38.2%

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access to sensitive information or conduct further attacks.

Affected configurations

Nvd
Vulners
Node
redhat3scale_api_managementMatch2.0
VendorProductVersionCPE
redhat3scale_api_management2.0cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "3scale-amp-system",
    "versions": [
      {
        "version": "3scale-amp-system as shipped in 3scale-AMP 2",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

38.2%

Related for CVE-2022-1414