Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2457

Опубликовано: 18 июл. 2022
Источник: redhat
CVSS3: 9.8

Описание

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

A flaw was found in Business Central in Red Hat Process Automation Manager 7. This flaw allows an attacker to benefit from a brute force attack in the Administration Console. In this issue, the application does not limit the number of unsuccessful login attempts.

Отчет

The impact is set to moderate as Brute Force is not very easy procedure to do depending upon the length and complexity of the password chosen.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Process Automation 7Business-centralAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-307
https://bugzilla.redhat.com/show_bug.cgi?id=2107990Business-central: admin console prone to brute force attack

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

CVSS3: 9.8
github
больше 3 лет назад

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

9.8 Critical

CVSS3