Description
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.
No analysis available yet.
Remediation
Vendor Solution
Update to 21.1.30 cloud version, or to 21.4.45 on premise version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27939 | Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication. |
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/departments/faq/cve_advisories |
|
History
No history.
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-09-17T02:27:31.416Z
Reserved: 2022-01-07T00:00:00.000Z
Link: CVE-2022-22796
No data.
Status : Modified
Published: 2022-05-12T20:15:14.847
Modified: 2024-11-21T06:47:28.293
Link: CVE-2022-22796
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD