HIGH🇵🇱 Wersja polska

CVE-2022-22551

CVSS 8.3v3.1pub. 2022-01-21upd. 2024-11-21

DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Dell Emc Appsync

    APP
    Dell
    < 4.4.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-24424HIGH7.5same product

Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote u...

CVE-2022-22553HIGH8.1same product

Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vuln...

CVE-2024-22464MEDIUM6.2same product

Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure o...

CVE-2022-22552MEDIUM6.9same product

Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated...

CVE-2024-39586LOW2.9same product

Dell AppSync Server w wersjach 4.3–4.6 zawiera podatność XML External Entity Injection. Zalogowany atakujący z...