Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-25152

Опубликовано: 09 июн. 2022
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a malicious actor (with a valid session token) can create a procedure, bypass approval, and execute the procedure. This results in the ability for any user with a valid session token to perform arbitrary code execution and full system take-over on all agents.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:itarian:on-premise:*:*:*:*:*:*:*:*
Версия до 6.35.37347.20040 (исключая)
cpe:2.3:a:itarian:saas_service_desk:*:*:*:*:*:*:*:*
Версия до 6.35.37347.20040 (исключая)

EPSS

Процентиль: 63%
0.00449
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-358
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a malicious actor (with a valid session token) can create a procedure, bypass approval, and execute the procedure. This results in the ability for any user with a valid session token to perform arbitrary code execution and full system take-over on all agents.

EPSS

Процентиль: 63%
0.00449
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-358
NVD-CWE-noinfo