First published: Fri Jan 21 2022(Updated: )
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC AppSync | <4.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22551 is considered a medium severity vulnerability due to its potential for session hijacking.
To mitigate CVE-2022-22551, upgrade Dell EMC AppSync to version 4.4.0.0 or later.
CVE-2022-22551 affects Dell EMC AppSync versions 3.9 to 4.3.
CVE-2022-22551 requires an adjacent, unauthenticated attacker to exploit the vulnerability.
CVE-2022-22551 involves the use of GET request methods with sensitive query strings, which can lead to session hijacking.