Lucene search

K
cvelistTR-CERTCVELIST:CVE-2022-2265
HistorySep 21, 2022 - 1:45 p.m.

CVE-2022-2265 Path traversal in Identity and Directory Management System

2022-09-2113:45:18
CWE-35
TR-CERT
www.cve.org
4
cve-2022-2265
path traversal
identity and directory management system
çekino bilgi teknolojileri
unauthenticated vulnerability
version 2.1.25 fixed

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

51.8%

The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Çekino Bilgi Teknolojileri",
    "vendor": "Çekino Bilgi Teknolojileri",
    "versions": [
      {
        "lessThan": "2.1.25",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

51.8%

Related for CVELIST:CVE-2022-2265