Lucene search

K
nvd[email protected]NVD:CVE-2022-1414
HistoryOct 19, 2022 - 6:15 p.m.

CVE-2022-1414

2022-10-1918:15:11
CWE-20
CWE-1173
web.nvd.nist.gov
2
3scale api management
user input
script injection
sensitive information

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

38.2%

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access to sensitive information or conduct further attacks.

Affected configurations

Nvd
Node
redhat3scale_api_managementMatch2.0
VendorProductVersionCPE
redhat3scale_api_management2.0cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

38.2%

Related for NVD:CVE-2022-1414