CVE-2022-32457: Data Systems Consulting Co., Ltd. BPM - Blind Server-Side Request Forgery (SSRF)
Published Jul 20, 2022
·Updated
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
Affected Software
1 affected component
Digiwin Business Process Management<5.8.8.1
Remediation
Information
Update version to 5.8.8.1
Event History
Jul 20, 2022
CVE Published
via MITRE·02:01 AM
Data Sourced
via MITRE·02:01 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-32457?
CVE-2022-32457 is identified as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2022-32457?
To mitigate CVE-2022-32457, upgrade Digiwin BPM to version 5.8.8.1 or later.
3
What type of attack does CVE-2022-32457 allow?
CVE-2022-32457 allows unauthenticated remote attackers to perform Blind SSRF attacks.
4
Which software is affected by CVE-2022-32457?
CVE-2022-32457 affects Digiwin Business Process Management software versions prior to 5.8.8.1.
5
What can attackers discover through CVE-2022-32457?
Attackers can potentially discover the internal network topology through URL error responses when exploiting CVE-2022-32457.