← volver
CVE-2022-38130explotación observada

CVE-2022-38130

52Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actepss 53%
de la publicación al arma
Publicada en NVD10 ago
VulnCheck+465d
probabilidad de explotación
53%top 1% de las CVE
explotación observada
VulnCheck
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.