Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-23292

Опубликовано: 12 апр. 2022
Источник: msrc
CVSS3: 3.7
EPSS Низкий

Описание

Microsoft Power BI Spoofing Vulnerability

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

The attack requires that multiple users try to use the gateway at the same time.

According to the CVSS, Scope is Changed. What is meant by scope change for this particular vulnerability?

A leaking impersonation session can lead to spoofing of another user account.

An attacker with.... privileges could access the data of another tenant.

According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability?

Information in the victim's browser associated with the vulnerable URL can be read by the malicious JavaScript code and sent to the attacker.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

Обновления

ПродуктСтатьяОбновление
Microsoft On-Premises Data Gateway

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 74%
0.00831
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
почти 4 года назад

Microsoft Power BI Spoofing Vulnerability

CVSS3: 5.9
github
почти 4 года назад

Microsoft Power BI Spoofing Vulnerability.

CVSS3: 5.9
fstec
почти 4 года назад

Уязвимость компонента Microsoft Power BI локального шлюза данных Microsoft On-Premises Data Gateway, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 74%
0.00831
Низкий

3.7 Low

CVSS3