CVE-2025-43022: Poly Clariti Manager - Multiple Security Vulnerabilities
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43022?
CVE-2025-43022 is classified as a high severity vulnerability due to the potential for SQL injection allowing privileged users to execute unauthorized SQL commands.
How do I fix CVE-2025-43022?
To fix CVE-2025-43022, update the Poly Clariti Manager to version 10.12.1 or later.
Which software is affected by CVE-2025-43022?
CVE-2025-43022 affects the Poly Clariti Manager versions prior to 10.12.1.
Who is responsible for addressing CVE-2025-43022?
HP is responsible for addressing CVE-2025-43022 by releasing a software update to mitigate the vulnerability.
Can privileged users exploit CVE-2025-43022?
Yes, privileged users can exploit CVE-2025-43022 to execute malicious SQL commands due to the SQL injection vulnerability.