HIGH🇵🇱 Wersja polska

CVE-2022-24424

CVSS 7.5v3.1pub. 2022-04-21upd. 2024-11-21

Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Dell Emc Appsync

    APP
    Dell
    3.9.0.0 – 4.4.0.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path TraversalAuth Bypass
CWE
References

Related vulnerabilities

CVE-2022-22551HIGH8.3same product

DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthe...

CVE-2022-22553HIGH8.1same product

Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vuln...

CVE-2024-22464MEDIUM6.2same product

Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure o...

CVE-2022-22552MEDIUM6.9same product

Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated...

CVE-2024-39586LOW2.9same product

Dell AppSync Server w wersjach 4.3–4.6 zawiera podatność XML External Entity Injection. Zalogowany atakujący z...