First published: Fri Jan 21 2022(Updated: )
Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC AppSync | <4.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22552 has been assigned a medium severity rating due to the potential for exploitation by remote unauthenticated attackers.
To fix CVE-2022-22552, upgrade Dell EMC AppSync to version 4.4.0.0 or later.
CVE-2022-22552 affects Dell EMC AppSync versions 3.9 through 4.3.
CVE-2022-22552 is associated with a clickjacking attack, which can trick users into performing unintended actions.
Yes, CVE-2022-22552 can be exploited by remote attackers without requiring any authentication.