5.4

CVE-2022-35221

TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or Throttling-2

Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attacker with general user privilege posting a thread subject with large content can cause the server to allocate too much memory, leading to missing partial post content and disrupt partial service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teamplus ≫ Team+ Pro SwEdition private_cloud SwPlatform android Version <= 3.011.6.0.1
Teamplus ≫ Team+ Pro SwEdition private_cloud SwPlatform iphone_os Version <= 3.011.6.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.521
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Cert TW 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://www.twcert.org.tw/tw/cp-132-6360-7bf50-1.html
Third Party Advisory