CVE-2022-35497: Trimble TM4Web vulnerability
In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.
Affected Software
Event History
Frequently Asked Questions
What access or interaction is required to exploit this issue?
An attacker would need to use the external document viewer endpoint to trigger reflected cross-site scripting. Successful exploitation can recover valid session cookies.
Which deployment component is affected?
The issue affects the external document viewer endpoint in Trimble TM4WEB 21.4.0.4. The provided information attributes the exposure to a session-identifier security misconfiguration.
How can defenders determine whether they may be exposed?
Review whether Trimble TM4WEB 21.4.0.4 is deployed and whether its external document viewer endpoint is accessible. The provided data does not include specific detection indicators or affected request patterns.