CVE Vulnerabilities

CVE-2022-22565

Improper Authorization of Index Containing Sensitive Information

Published: Apr 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
3.8
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Dell PowerScale OneFS, versions 9.0.0-9.3.0, contain an improper authorization of index containing sensitive information. An authenticated and privileged user could potentially exploit this vulnerability, leading to disclosure or modification of sensitive data.

Weakness

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Affected Software

Name Vendor Start Version End Version
Emc_powerscale_onefs Dell 8.2.0 (including) 9.3.0 (including)

References