CVE-2022-3217: High severity visam vbase pro-rt/ server-rt (web remote) vulnerability
Published Sep 16, 2022
·Updated
When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the ability to capture a login session can obtain the login credentials.
Affected Software
1 affected component
VISAM VBASE=11.7.0.2
Event History
Sep 16, 2022
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3217?
CVE-2022-3217 is considered a high severity vulnerability due to its potential for credential theft.
2
How do I fix CVE-2022-3217?
To mitigate CVE-2022-3217, ensure to implement a more secure authentication method that does not rely on static keys.
3
Who is affected by CVE-2022-3217?
CVE-2022-3217 affects users of VBASE version 11.7.0.2.
4
What kind of attack is possible with CVE-2022-3217?
CVE-2022-3217 allows an unauthenticated remote attacker to capture and decipher login credentials.
5
What products are involved in CVE-2022-3217?
The vulnerability CVE-2022-3217 involves the VISAM VBASE application.