CVE-2022-22552: Medium severity dell emc appsync vulnerability
Published Jan 21, 2022
·Updated
Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.
Affected Software
1 affected component
Dell EMC AppSync<4.4.0.0
Remediation
Patch Available
Event History
Jan 21, 2022
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22552?
CVE-2022-22552 has been assigned a medium severity rating due to the potential for exploitation by remote unauthenticated attackers.
2
How do I fix CVE-2022-22552?
To fix CVE-2022-22552, upgrade Dell EMC AppSync to version 4.4.0.0 or later.
3
Who is affected by CVE-2022-22552?
CVE-2022-22552 affects Dell EMC AppSync versions 3.9 through 4.3.
4
What type of attack is associated with CVE-2022-22552?
CVE-2022-22552 is associated with a clickjacking attack, which can trick users into performing unintended actions.
5
Can CVE-2022-22552 be exploited without authentication?
Yes, CVE-2022-22552 can be exploited by remote attackers without requiring any authentication.