Risk | High |
Patch available | YES |
Number of vulnerabilities | 10 |
CVE-ID | CVE-2022-21618 CVE-2022-21619 CVE-2022-21624 CVE-2022-21626 CVE-2022-21628 CVE-2022-39399 CVE-2022-34305 CVE-2022-42252 CVE-2022-45143 CVE-2022-31692 |
CWE-ID | CWE-20 CWE-79 CWE-444 CWE-94 CWE-285 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #7 is available. |
Vulnerable software Subscribe |
Dell Policy Manager for Secure Connect Gateway (SCG) Other software / Other software solutions |
Vendor | Dell |
Security Bulletin
This security bulletin contains information about 10 vulnerabilities.
EUVDB-ID: #VU68439
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21618
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper input validation within the JGSS component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68442
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-21619
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper input validation within the Security component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68441
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-21624
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper input validation within the JNDI component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68438
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21626
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to perform service disruption.
The vulnerability exists due to improper input validation within the Security component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to perform service disruption.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68437
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21628
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to perform service disruption.
The vulnerability exists due to improper input validation within the Lightweight HTTP Server component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to perform service disruption.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68440
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-39399
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper input validation within the Networking component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU64627
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-34305
CWE-ID:
Exploit availability:
DescriptionThe disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed to the form authentication example in the examples web application. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68859
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-42252
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers via an invalid
Content-Length
header.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks but requires Tomcat to be configured to ignore invalid HTTP headers via setting
rejectIllegalHeader
to false
(not the default configuration).
Install update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU70666
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-45143
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to manipulate server output.
The vulnerability exists due to improper input validation within the JsonErrorReportValve when handling type, message or description values. A remote attacker can send a specially crafted request and manipulate or invalidate JSON output.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68866
Risk: High
CVSSv3.1:
CVE-ID: CVE-2022-31692
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to authorization rules bypass via forward or include dispatcher types. A remote attacker can bypass authorization process.
MitigationInstall update from vendor's website.
Vulnerable software versionsDell Policy Manager for Secure Connect Gateway (SCG): before 5.14.00.14
Fixed software versionsCPE2.3 External links
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?