DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
References
Link | Resource |
---|---|
https://www.dell.com/support/kbdoc/000195377 | Patch Vendor Advisory |
Configurations
Information
Published : 2022-01-21 13:15
Updated : 2022-01-27 07:00
NVD link : CVE-2022-22551
Mitre link : CVE-2022-22551
JSON object : View
CWE
CWE-384
Session Fixation
Products Affected
dell
- emc_appsync