Lucene search

K
nvd[email protected]NVD:CVE-2022-39038
HistoryNov 10, 2022 - 3:15 p.m.

CVE-2022-39038

2022-11-1015:15:14
CWE-287
web.nvd.nist.gov
3
agentflow bpm
authentication
vulnerability
remote attacker
user privilege
account privilege
system manipulation

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

61.9%

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.

Affected configurations

Nvd
Node
flowringagentflowMatch4.0.0.1183.552
VendorProductVersionCPE
flowringagentflow4.0.0.1183.552cpe:2.3:a:flowring:agentflow:4.0.0.1183.552:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

61.9%

Related for NVD:CVE-2022-39038