CVE-2022-22551: High severity dell emc appsync vulnerability
Published Jan 21, 2022
·Updated
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
Affected Software
1 affected component
Dell EMC AppSync<4.4.0.0
Remediation
Patch Available
Event History
Jan 21, 2022
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22551?
CVE-2022-22551 is considered a medium severity vulnerability due to its potential for session hijacking.
2
How do I fix CVE-2022-22551?
To mitigate CVE-2022-22551, upgrade Dell EMC AppSync to version 4.4.0.0 or later.
3
Who is affected by CVE-2022-22551?
CVE-2022-22551 affects Dell EMC AppSync versions 3.9 to 4.3.
4
Can CVE-2022-22551 be exploited remotely?
CVE-2022-22551 requires an adjacent, unauthenticated attacker to exploit the vulnerability.
5
What does CVE-2022-22551 involve?
CVE-2022-22551 involves the use of GET request methods with sensitive query strings, which can lead to session hijacking.