CVE-2022-29847: SSRF
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29847?
CVE-2022-29847 is a vulnerability in Ipswitch WhatsUp Gold 21.0.0 through 21.1.1 and 22.0.0 that allows an unauthenticated attacker to relay encrypted user credentials to an arbitrary host.
How does CVE-2022-29847 impact Ipswitch WhatsUp Gold?
CVE-2022-29847 allows an unauthenticated attacker to relay encrypted user credentials in Ipswitch WhatsUp Gold to an arbitrary host.
What is the severity of CVE-2022-29847?
CVE-2022-29847 has a severity rating of 7.5 (high).
How can I fix CVE-2022-29847?
To fix CVE-2022-29847, it is recommended to apply the latest patches and updates provided by Ipswitch WhatsUp Gold.
Where can I find more information about CVE-2022-29847?
More information about CVE-2022-29847 can be found in the official advisory from Ipswitch and the Progress community website.