Lucene search

K
cvelistMitreCVELIST:CVE-2022-25237
HistoryMay 27, 2022 - 4:48 p.m.

CVE-2022-25237

2022-05-2716:48:43
mitre
www.cve.org
5
bonita web 2021.2
authentication bypass
vulnerability
restapiauthorizationfilter
remote code execution
privileged api

AI Score

9.8

Confidence

High

EPSS

0.348

Percentile

97.1%

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /…/i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

AI Score

9.8

Confidence

High

EPSS

0.348

Percentile

97.1%

Related for CVELIST:CVE-2022-25237