« Volver al listado

CVE-2022-1731

Estado: ModificadaCrítica (9.8)—

Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-1731",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vulnreport@tenable.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Metasonic Doc WebClient",
          "versions": [
            {
              "status": "affected",
              "version": "Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-16T19:15:07.903",
  "references": [
    {
      "url": "https://www.tenable.com/security/research/tra-2022-17",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "vulnreport@tenable.com"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2022-17",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist."
    },
    {
      "lang": "es",
      "value": "Metasonic Doc WebClient versiones 7.0.14.0 / 7.0.12.0 / 7.0.3.0, son vulnerables a un ataque de inyección SQL en el campo username. Es requerido que el SSO o la autenticación del sistema estén habilitados para que se presenten las condiciones de vulnerabilidad"
    }
  ],
  "lastModified": "2026-06-17T04:23:00.037",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:allgeier:metasonic_doc_webclient:7.0.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4D258F2-13DC-4B87-B371-896850EE9EFB"
            },
            {
              "criteria": "cpe:2.3:a:allgeier:metasonic_doc_webclient:7.0.12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "022C9410-EE1B-4B49-AB3B-EAC503ACC4DD"
            },
            {
              "criteria": "cpe:2.3:a:allgeier:metasonic_doc_webclient:7.0.14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7ADE391A-0C63-49A1-96D9-933FE9356572"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnreport@tenable.com"
}