CVE-2022-39214: Authenticated users of Combodo iTop can take over any account
Published Mar 14, 2023
·Updated
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.
Affected Software
2 affected components
iTop<2.7.8
iTop>3.0.0<3.0.2-1
Remediation
Event History
Mar 14, 2023
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-39214?
CVE-2022-39214 is a vulnerability in Combodo iTop, a web-based IT service management platform, that allows a user to take over any account by knowing the account's username.
2
What is the severity of CVE-2022-39214?
CVE-2022-39214 has a severity rating of critical with a score of 7.5.
3
How can I fix CVE-2022-39214?
To fix CVE-2022-39214, you should update to iTop versions 2.7.8 or 3.0.2-1, which have the issue resolved.
4
Is CVE-2022-39214 fixed in the latest version of iTop?
Yes, CVE-2022-39214 is fixed in iTop versions 2.7.8 and 3.0.2-1.
5
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-39214?
The CWE ID associated with CVE-2022-39214 is 863.