Vulnerability Name:

CVE-2022-22637 (CCN-221764)

Assigned:2022-03-14
Published:2022-03-14
Updated:2022-09-28
Summary:A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
8.8 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2022-22637

Source: XF
Type: UNKNOWN
apple-ios-cve202222637-sec-bypass(221764)

Source: CCN
Type: Apple security document HT213182
About the security content of iOS 15.4 and iPadOS 15.4

Source: MISC
Type: Vendor Advisory
https://support.apple.com/en-us/HT213182

Source: MISC
Type: Vendor Advisory
https://support.apple.com/en-us/HT213183

Source: MISC
Type: Vendor Advisory
https://support.apple.com/en-us/HT213186

Source: CCN
Type: Apple security document HT213187
About the security content of Safari 15.4

Source: MISC
Type: Vendor Advisory
https://support.apple.com/en-us/HT213187

Source: MISC
Type: Vendor Advisory
https://support.apple.com/en-us/HT213193

Source: CCN
Type: Mend Vulnerability Database
CVE-2022-22637

Vulnerable Configuration:Configuration 1:
  • cpe:/o:apple:tvos:*:*:*:*:*:*:*:* (Version < 15.4)
  • OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 15.4)
  • OR cpe:/o:apple:watchos:*:*:*:*:*:*:*:* (Version < 8.5)
  • OR cpe:/o:apple:macos:*:*:*:*:*:*:*:* (Version >= 12.0 and < 12.3)
  • OR cpe:/a:apple:safari:*:*:*:*:*:*:*:* (Version < 15.4)
  • OR cpe:/o:apple:ipados:*:*:*:*:*:*:*:* (Version < 15.4)

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8033
    P
    libjavascriptcoregtk-5_0-0-2.38.6-150400.4.39.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7603
    P
    libjavascriptcoregtk-4_0-18-2.38.6-150400.4.39.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7941
    P
    libjavascriptcoregtk-4_1-0-2.38.6-150400.4.39.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3401
    P
    xen-4.12.1_06-1.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3018
    P
    augeas-1.10.1-2.6 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3320
    P
    pam_yubico-2.26-1.25 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94648
    P
    libjavascriptcoregtk-4_0-18-2.36.0-150400.2.13 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94950
    P
    libjavascriptcoregtk-4_1-0-2.36.0-150400.2.13 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95031
    P
    libjavascriptcoregtk-5_0-0-2.36.0-150400.2.12 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:127272
    P
    Security update for webkit2gtk3 (Important)
    2022-05-16
    oval:org.opensuse.security:def:5239
    P
    Security update for webkit2gtk3 (Important)
    2022-05-16
    oval:org.opensuse.security:def:125709
    P
    Security update for webkit2gtk3 (Important)
    2022-05-16
    oval:org.opensuse.security:def:6037
    P
    Security update for webkit2gtk3 (Important)
    2022-05-16
    oval:org.opensuse.security:def:126875
    P
    Security update for webkit2gtk3 (Important)
    2022-05-16
    oval:com.redhat.rhsa:def:20221777
    P
    RHSA-2022:1777: webkit2gtk3 security, bug fix, and enhancement update (Moderate)
    2022-05-10
    oval:org.opensuse.security:def:118885
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:101596
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:119567
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:1064
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:451
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:119077
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:101755
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:119192
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:118695
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:119382
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    oval:org.opensuse.security:def:865
    P
    Security update for webkit2gtk3 (Important)
    2022-04-27
    BACK
    apple tvos *
    apple iphone os *
    apple watchos *
    apple macos *
    apple safari *
    apple ipad os *