ZeroHour

CVE-2022-21939

CVSS 3.1
6.1 medium
EPSS
<1%p44
Published
()
Modified
Description

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Vendors
johnsoncontrols
Products
metasys system configuration tool
Weakness
CWE-1004, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.