Lucene search

K
cveM-Files CorporationCVE-2022-3284
HistoryMar 06, 2023 - 11:15 a.m.

CVE-2022-3284

2023-03-0611:15:10
CWE-200
M-Files Corporation
web.nvd.nist.gov
26
cve-2022-3284
m-files
new web
vulnerability
download key
insecure
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.7%

Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0.
This issue affects M-Files New Web: before 22.11.12011.0.

Affected configurations

Nvd
Node
m-filesm-files_serverRange<22.11.12011.0
VendorProductVersionCPE
m-filesm-files_server*cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "M-Files New Web",
    "vendor": "M-Files",
    "versions": [
      {
        "lessThan": "22.11.12011.0",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.7%

Related for CVE-2022-3284