CVE-2022-39039: aEnrich a+HRD - Server-Side Request Forgery (SSRF)
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-39039?
CVE-2022-39039 is a vulnerability in aEnrich's a+HRD software that allows an unauthenticated remote attacker to perform Server-Side Request Forgery (SSRF) attacks, execute arbitrary system commands, or disrupt services.
What is the severity level of CVE-2022-39039?
The severity level of CVE-2022-39039 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-39039?
The affected versions of the aEnrich's a+HRD software are 6.8 and 7.0.
How can an attacker exploit CVE-2022-39039?
An attacker can exploit CVE-2022-39039 by sending arbitrary HTTP(s) requests and launching Server-Side Request Forgery (SSRF) attacks, executing arbitrary system commands, or disrupting services.
Where can I find more information about CVE-2022-39039?
More information about CVE-2022-39039 can be found at the following reference: [https://www.twcert.org.tw/tw/cp-132-6792-c4a62-1.html](https://www.twcert.org.tw/tw/cp-132-6792-c4a62-1.html)