CVE Vulnerabilities

CVE-2022-45183

Improper Privilege Management

Published: Nov 14, 2022 | Modified: Nov 16, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Powershell_universal Ironmansoftware 2.0.0 (including) 2.12.6 (excluding)
Powershell_universal Ironmansoftware 3.0.0 (including) 3.4.7 (excluding)
Powershell_universal Ironmansoftware 3.5.0 (including) 3.5.3 (excluding)

Potential Mitigations

References