CVE-2022-38657: An open redirect to malicious sites affects HCL Leap
Published Feb 2, 2023
·Updated
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
Affected Software
1 affected component
hcltech Hcl Leap<9.3
Event History
Feb 2, 2023
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
DescriptionSeverity
Feb 12, 2023
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-38657?
CVE-2022-38657 is a vulnerability that allows open redirects to malicious sites when accessing the "Feedback" action on the manager page.
2
What software is affected by CVE-2022-38657?
Hcltech Hcl Leap version up to 9.3 is affected by CVE-2022-38657.
3
How can I fix CVE-2022-38657?
Apply the latest update or patch provided by Hcltech to fix the vulnerability.
4
What is the severity of CVE-2022-38657?
CVE-2022-38657 has a severity rating of 5.4 (High).
5
Where can I find more information about CVE-2022-38657?
You can find more information about CVE-2022-38657 at the following link: [link](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0097201)