Description
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.
Published: 2022-06-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.5.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-27094 Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.
History

No history.

Subscriptions

Johnsoncontrols Metasys Application And Data Server Metasys Extended Application And Data Server Metasys Open Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2024-09-16T17:19:16.453Z

Reserved: 2021-12-15T00:00:00.000Z

Link: CVE-2022-21938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-15T21:15:09.190

Modified: 2024-11-21T06:45:44.787

Link: CVE-2022-21938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses