VulnerabilityModified
CVE-2022-32457
An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
MEDIUM 5.3EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.80% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- digiwin/business process management
- Source
- twcert@cert.org.tw
References
- https://www.chtsecurity.com/news/09757883-fea6-4aff-9e22-8ae8c4f8f7bbThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-6287-20ef0-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/09757883-fea6-4aff-9e22-8ae8c4f8f7bbThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-6287-20ef0-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.