ZeroHour

CVE-2022-32457

CVSS 3.1
5.3 medium
EPSS
<1%p54
Published
()
Modified
Description

Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.

Vendors
digiwin
Products
business process management
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.