CRITICAL

CVE-2022-25237

CVSS v3

9.8

CRITICAL

EPSS Score

92.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

Technical details

Published
6/2/2022

Frequently asked questions

What is CVE-2022-25237?

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

Is CVE-2022-25237 actively exploited?

Active exploitation of CVE-2022-25237 has not been confirmed. The EPSS score is 92.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-25237?

CVE-2022-25237 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-25237 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.