9
CVE-2022-1065
- EPSS 1.63%
- Veröffentlicht 19.04.2022 08:15:06
- Zuletzt bearbeitet 21.11.2024 06:39:57
- Quelle vulnerability@ncsc.ch
- Teams Watchlist Login
- Unerledigt Login
A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions prior to R4 of 2022-01-15; v2020 versions prior to R6 of 2022-01-15; v2019 versions later than R5 (service pack); v2018 versions later than R5 (service pack). This issue does not affect: Abacus ERP v2019 versions prior to R5 of 2020-03-15; v2018 versions prior to R7 of 2020-04-15; v2017 version and prior versions and prior versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Abacus ≫ Abacus Erp 2018 Version >= r7
Abacus ≫ Abacus Erp 2019 Version >= r5
Abacus ≫ Abacus Erp 2020 Version < r6
Abacus ≫ Abacus Erp 2021 Version < r4
Abacus ≫ Abacus Erp 2022 Version < r1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.63% | 0.809 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
vulnerability@ncsc.ch | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-304 Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.