Vulnerability Name: | CVE-2022-34716 (CCN-232148) | ||||||||||||||||||
Assigned: | 2022-08-09 | ||||||||||||||||||
Published: | 2022-08-09 | ||||||||||||||||||
Updated: | 2023-05-31 | ||||||||||||||||||
Summary: | |||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
5.3 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:N/A:N)
| ||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-34716 Source: XF Type: UNKNOWN ms-dotnet-cve202234716-spoofing(232148) Source: secure@microsoft.com Type: UNKNOWN secure@microsoft.com Source: CCN Type: Packet Storm Security [09-09-2022] .NET XML Signature Verification External Entity Injection Source: CCN Type: Microsoft Security TechCenter - August 2022 CVE-2022-34716 - .NET Spoofing Vulnerability Source: CCN Type: IBM Security Bulletin 6825149 (Robotic Process Automation) IBM Robotic Process Automation may be vulnerable to spoofing attacks due to System.Security.Cryptography.Xml (CVE-2022-34716)) | ||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |