CVE-2022-38130
52Vexday Risk Score
Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.
ssvc Actepss 54%
da publicação à arma
Publicada no NVD10 de ago.
VulnCheck+465d
probabilidade de exploração
54%top 1% das CVEs
exploração observada
simVulnCheck
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.
Produtos afetados
n/a · Keysight Technologies Sensor Management Server