First published: Wed Nov 30 2022(Updated: )
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | <22.3.11237.3 |
Upgrade to non-affected version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1606 is a vulnerability in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 that allows a user to read unmanaged objects due to incorrect privilege assignment.
The severity of CVE-2022-1606 is medium with a CVSS score of 4.3.
CVE-2022-1606 allows a user to read unmanaged objects in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1.
To fix CVE-2022-1606, update your M-Files Server to version 22.3.11164.0 or later.
You can find more information about CVE-2022-1606 on the M-Files Trust Center Security Advisories page: https://www.m-files.com/about/trust-center/security-advisories/cve-2022-1606/