Show plain JSON{"id": "CVE-2022-45166", "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "cve@mitre.org", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.5, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 2.8}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 4.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 2.8}]}, "published": "2023-01-10T21:15:12.610", "references": [{"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-45166/", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2022-45166/", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role."}, {"lang": "es", "value": "Se descubri\u00f3 un problema en Archibus Web Central 2022.03.01.107. Un servicio expuesto por la aplicaci\u00f3n acepta un conjunto de par\u00e1metros controlados por el usuario que se utilizan para actuar sobre los datos devueltos al usuario. Permite a un usuario b\u00e1sico acceder a datos no relacionados con su funci\u00f3n."}], "lastModified": "2024-11-21T07:28:52.643", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:archibus:archibus_web_central:2022.03.01.107:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "931FD477-1364-4A7E-9C4D-74F1CE19AB6A"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}