CVE-2022-45166

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role.
Configurations

Configuration 1 (hide)

cpe:2.3:a:archibus:archibus_web_central:2022.03.01.107:*:*:*:*:*:*:*

History

09 Apr 2025, 16:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 07:28

Type Values Removed Values Added
References () https://excellium-services.com/cert-xlm-advisory/CVE-2022-45166/ - Third Party Advisory () https://excellium-services.com/cert-xlm-advisory/CVE-2022-45166/ - Third Party Advisory
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 6.5
Summary
  • (es) Se descubrió un problema en Archibus Web Central 2022.03.01.107. Un servicio expuesto por la aplicación acepta un conjunto de parámetros controlados por el usuario que se utilizan para actuar sobre los datos devueltos al usuario. Permite a un usuario básico acceder a datos no relacionados con su función.

Information

Published : 2023-01-10 21:15

Updated : 2025-04-09 16:15


NVD link : CVE-2022-45166

Mitre link : CVE-2022-45166

CVE.ORG link : CVE-2022-45166


JSON object : View

Products Affected

archibus

  • archibus_web_central
CWE
NVD-CWE-Other CWE-284

Improper Access Control