CVE-2022-22976
Published on: Not Yet Published
Last Modified on: 02/03/2023 01:45:00 AM UTC
Certain versions of Active Iq Unified Manager from Netapp contain the following vulnerability:
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.
- CVE-2022-22976 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
May 2022 Spring Security Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
CVE-2022-22976 | Security | VMware Tanzu | tanzu.vmware.com text/html |
![]() |
Oracle Critical Patch Update Advisory - July 2022 | www.oracle.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Netapp | Active Iq Unified Manager | - | All | All | All |
Application | Netapp | Active Iq Unified Manager | - | All | All | All |
Application | Netapp | Active Iq Unified Manager | - | All | All | All |
Application | Oracle | Financial Services Crime And Compliance Management Studio | 8.0.8.2.0 | All | All | All |
Application | Oracle | Financial Services Crime And Compliance Management Studio | 8.0.8.3.0 | All | All | All |
Application | Vmware | Spring Security | All | All | All | All |
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*:
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*:
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*:
- cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Spring Security 5.7.0, 5.6.4, 5.5.7 Released - Fixes CVE-2022-22975 & CVE-2022-22976 spring.io/blog/2022/05/1… | 2022-05-16 22:48:27 |
![]() |
Spring Security 5.7.0, 5.6.4, 5.5.7 Released - Fixes CVE-2022-22975 & CVE-2022-22976 dlvr.it/SQVR44 | 2022-05-17 01:01:02 |
![]() |
CVE-2022-22976: BCrypt skips salt rounds for work factor of 31 dlvr.it/SQVjr0 | 2022-05-17 04:01:33 |
![]() |
The vuln CVE-2022-22976 has a tweet created 0 days ago and retweeted 11 times. twitter.com/SpringSecurity… #pow1rtrtwwcve | 2022-05-17 04:06:01 |
![]() |
Spring Security 5.7.0, 5.6.4, 5.5.7 发布修复 CVE-2022-22978 & CVE-2022-22976 ift.tt/jmKcIUa | 2022-05-18 00:16:38 |
![]() |
CVE-2022-22976 : Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versi… twitter.com/i/web/status/1… | 2022-05-19 15:08:55 |
![]() |
Spring - CVE-2022-22976: tanzu.vmware.com/security/cve-2… | 2022-05-19 17:00:33 |
![]() |
CVE-2022-22976 | 2022-05-19 16:38:56 |