First published: Tue Jun 14 2022(Updated: )
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions < V13.1.0.9), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter V14.0 (All versions < V14.0.0.2). Java EE Server Manager HTML Adaptor in Teamcenter consists of default hardcoded credentials. Access to the application allows a user to perform a series of actions that could potentially lead to remote code execution with elevated permissions.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Teamcenter | >=12.4<12.4.0.13 | |
Siemens Teamcenter | >=13.0<13.0.0.9 | |
Siemens Teamcenter | >=13.1<13.1.0.9 | |
Siemens Teamcenter | >=13.2<13.2.0.9 | |
Siemens Teamcenter | >=13.3<13.3.0.3 | |
Siemens Teamcenter | >=14.0<14.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Teamcenter vulnerability is CVE-2022-31619.
This vulnerability affects Teamcenter versions 12.4 (All versions < V12.4.0.13), 13.0 (All versions < V13.0.0.9), 13.1 (All versions < V13.1.0.9), 13.2 (All versions < V13.2.0.9), 13.3 (All versions < V13.3.0.3), and 14.0 (All versions < V14.0.0.2).
The severity of CVE-2022-31619 is high with a severity value of 8.8.
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2022-31619.
To fix the vulnerability in Teamcenter, update to version V12.4.0.13 or later for Teamcenter V12.4, update to version V13.0.0.9 or later for Teamcenter V13.0, update to version V13.1.0.9 or later for Teamcenter V13.1, update to version V13.2.0.9 or later for Teamcenter V13.2, update to version V13.3.0.3 or later for Teamcenter V13.3, and update to version V14.0.0.2 or later for Teamcenter V14.0.