| Vulnerability Name: | CVE-2022-34716 (CCN-232148) | ||||||||||||||||||
| Assigned: | 2022-08-09 | ||||||||||||||||||
| Published: | 2022-08-09 | ||||||||||||||||||
| Updated: | 2023-05-31 | ||||||||||||||||||
| Summary: | |||||||||||||||||||
| CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
5.3 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
| ||||||||||||||||||
| CVSS v2 Severity: | 5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:N/A:N)
| ||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2022-34716 Source: XF Type: UNKNOWN ms-dotnet-cve202234716-spoofing(232148) Source: secure@microsoft.com Type: UNKNOWN secure@microsoft.com Source: CCN Type: Packet Storm Security [09-09-2022] .NET XML Signature Verification External Entity Injection Source: CCN Type: Microsoft Security TechCenter - August 2022 CVE-2022-34716 - .NET Spoofing Vulnerability Source: CCN Type: IBM Security Bulletin 6825149 (Robotic Process Automation) IBM Robotic Process Automation may be vulnerable to spoofing attacks due to System.Security.Cryptography.Xml (CVE-2022-34716)) | ||||||||||||||||||
| Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||
| Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
| BACK | |||||||||||||||||||