CVE-2022-21939: Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Affected Software
Remediation
Information
Information
Information
Event History
Frequently Asked Questions
What is CVE-2022-21939?
CVE-2022-21939 is a vulnerability in Johnson Controls System Configuration Tool (SCT) versions 14.0 to 14.2.3 and versions 15.0 to 15.0.3.
What is the severity of CVE-2022-21939?
The severity of CVE-2022-21939 is high with a CVSS score of 6.1.
What is the description of CVE-2022-21939?
CVE-2022-21939 is a Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) that could allow unauthorized access to the cookie.
Which software versions are affected by CVE-2022-21939?
Johnson Controls System Configuration Tool (SCT) versions 14 prior to 14.2.3 and versions 15 prior to 15.0.3 are affected by CVE-2022-21939.
How can I fix CVE-2022-21939?
To fix CVE-2022-21939, update Johnson Controls System Configuration Tool (SCT) to version 14.2.3 or 15.0.3 or later.