SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-25626

However, the system doesn’t allow the user to carry out server side tasks without a valid web session.

MEDIUM 5.3EPSS 0.69%

Does this matter?

Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.

Description

An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.69% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-425
Affected
broadcom/symantec identity governance and administration
Source
secure@symantec.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.