4.9

CVE-2022-4861

Incorrect Implementation of Authentication Algorithm

Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
M-filesM-files Client Version < 22.5.11356.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.415
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
security@m-files.com 4.8 0.5 4.2
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-303 Incorrect Implementation of Authentication Algorithm

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

https://product.m-files.com/security-advisories/cve-2022-4861/
https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4861/
Broken Link
https://empower.m-files.com/security-advisories/CVE-2022-4861