Lucene search

K
cveHCLCVE-2022-38657
HistoryFeb 12, 2023 - 4:15 a.m.

CVE-2022-38657

2023-02-1204:15:14
CWE-601
HCL
web.nvd.nist.gov
27
cve-2022-38657
open redirect
malicious sites
feedback action
manager page

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

23.5%

An open redirect to malicious sites can occur when accessing the “Feedback” action on the manager page.

Affected configurations

Nvd
Node
hcltechhcl_leapRange<9.3
VendorProductVersionCPE
hcltechhcl_leap*cpe:2.3:a:hcltech:hcl_leap:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Leap",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "< 9.3"
      }
    ]
  }
]

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

23.5%

Related for CVE-2022-38657