Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: twcert

Published: 2022-07-11T00:00:00

Updated: 2022-08-09T20:07:25

Reserved: 2022-06-06T00:00:00


Link: CVE-2022-32457

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-07-20T02:15:07.487

Modified: 2022-09-14T21:02:33.620


Link: CVE-2022-32457

JSON object: View

cve-icon Redhat Information

No data.

CWE