Lucene search

K
nvd[email protected]NVD:CVE-2022-2265
HistorySep 21, 2022 - 2:15 p.m.

CVE-2022-2265

2022-09-2114:15:11
CWE-22
CWE-35
web.nvd.nist.gov
2
identity directory management system
path traversal
vulnerability
version 2.1.25

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

51.8%

The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25

Affected configurations

Nvd
Node
identity_and_directory_management_system_projectidentity_and_directory_management_systemRange<2.1.25
VendorProductVersionCPE
identity_and_directory_management_system_projectidentity_and_directory_management_system*cpe:2.3:a:identity_and_directory_management_system_project:identity_and_directory_management_system:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

51.8%

Related for NVD:CVE-2022-2265