CVE-2022-22916: Critical severity Zoneland O2oa vulnerability
Published Feb 17, 2022
·Updated
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /xprogramcenter/jaxrs/invoke.
Affected Software
1 affected component
Zoneland O2oa=6.4.7
Event History
Feb 17, 2022
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-22916?
CVE-2022-22916 is a remote code execution (RCE) vulnerability found in O2OA v6.4.7.
2
How severe is CVE-2022-22916?
CVE-2022-22916 is classified as critical with a severity score of 9.8.
3
How does CVE-2022-22916 impact O2OA v6.4.7?
CVE-2022-22916 allows remote attackers to execute arbitrary code on systems running O2OA v6.4.7 via the /x_program_center/jaxrs/invoke endpoint.
4
Is there a fix available for CVE-2022-22916?
At the moment, there is no official fix available for CVE-2022-22916. It is recommended to stay updated with the latest security advisories and patches provided by the vendor.
5
Where can I find more information about O2OA v6.4.7?
You can find more information about O2OA v6.4.7 on the official website at http://o2oa.com.