« Volver al listado

CVE-2022-24669

Estado: ModificadaMedia (6.5)—

It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-24669",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-24669",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-06T18:33:01.889737Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@forgerock.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@forgerock.com",
      "affectedData": [
        {
          "vendor": "ForgeRock",
          "product": "Access Management",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "6.5.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "7.1.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "7.2.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-27T17:15:09.683",
  "references": [
    {
      "url": "https://backstage.forgerock.com/downloads/browse/am/featured",
      "tags": [
        "Product"
      ],
      "source": "psirt@forgerock.com"
    },
    {
      "url": "https://backstage.forgerock.com/knowledge/kb/article/a90639318",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@forgerock.com"
    },
    {
      "url": "https://backstage.forgerock.com/downloads/browse/am/featured",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://backstage.forgerock.com/knowledge/kb/article/a90639318",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@forgerock.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services."
    },
    {
      "lang": "es",
      "value": "Quizás sea posible obtener algunos detalles del despliegue mediante un ataque bien elaborado. Esto puede permitir que esos datos se utilicen para sondear los servicios de la red interna."
    }
  ],
  "lastModified": "2026-06-17T04:32:15.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4162CDDD-B604-4B3C-AAA1-14D33FE1EF45",
              "versionEndIncluding": "6.0.0.7",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D9D6502-4993-46CE-9FDC-71808D76C416",
              "versionEndIncluding": "6.5.0.2",
              "versionStartIncluding": "6.5.0"
            },
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9AC242A-391E-463D-8C00-28CE22D6339E",
              "versionEndIncluding": "6.5.2.3",
              "versionStartIncluding": "6.5.2.1"
            },
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D66C82CB-63C8-4A3C-AD19-08CD666F8C9D",
              "versionEndIncluding": "7.0.2",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:6.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E31AD7C7-9145-4EBC-A1A1-531B77BEFB0C"
            },
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:6.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3D7F2DE-8E77-4268-9F8B-D95954A31140"
            },
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:6.5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4CB42E3-B330-4202-87A4-EC503D569C78"
            },
            {
              "criteria": "cpe:2.3:a:forgerock:access_management:7.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9725E909-8707-402E-939B-EC6FA6FA0984"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@forgerock.com"
}