CVE-2022-22280: SQL Injection
Published Jul 29, 2022
·Updated
Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions.
Affected Software
3 affected components
SonicWall Analytics<=2.5.0.3-2520
SonicWall Global Management System<9.3.1
SonicWall Global Management System=9.3.1
Event History
Jul 29, 2022
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-22280?
CVE-2022-22280 is an SQL Injection vulnerability impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520, and earlier versions.
2
How severe is CVE-2022-22280?
CVE-2022-22280 has a severity score of 9.8 (Critical).
3
Which software versions are affected by CVE-2022-22280?
CVE-2022-22280 impacts SonicWall Global Management System (GMS) 9.3.1-SP2-Hotfix1 and SonicWall Analytics On-Prem 2.5.0.3-2520, as well as earlier versions.
4
What is the CWE ID for CVE-2022-22280?
CVE-2022-22280 has the CWE ID 89.
5
How can I fix CVE-2022-22280?
To fix CVE-2022-22280, it is recommended to upgrade SonicWall GMS and Analytics On-Prem to the latest versions available.