Lucene search

K
cveRedhatCVE-2022-2457
HistoryAug 10, 2022 - 8:15 p.m.

CVE-2022-2457

2022-08-1020:15:36
CWE-307
redhat
web.nvd.nist.gov
38
4
red hat
process automation manager
cve-2022-2457
security
flaw
brute force
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

53.9%

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

Affected configurations

Nvd
Vulners
Node
redhatprocess_automation_managerRange<7.13.2
VendorProductVersionCPE
redhatprocess_automation_manager*cpe:2.3:a:redhat:process_automation_manager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Red Hat Process Automation Manager 7",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in 7.13.2"
      }
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

53.9%

Related for CVE-2022-2457