Exposure of Resource to Wrong Sphere in spring-boot - CVE-2022-27772
Published: July 27, 2022
Vulnerability identifier: #VU65829
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27772
CWE-ID: CWE-668
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a temporary directory hijacking. A local user can trigger the vulnerability and escalate privileges on the system.
Affected software
spring-boot
Dell Secure Connect Gateway
watsonx.data
Storage Copy Data Management
Storage Protect Plus Server
Dell EMC VxRail Appliance
Dell Secure Connect Gateway
watsonx.data
Storage Copy Data Management
Storage Protect Plus Server
Dell EMC VxRail Appliance
How to mitigate CVE-2022-27772
Install updates from vendor's website.
spring-boot - update to 2.2.11
Dell Secure Connect Gateway - update to 5.12.00.10
watsonx.data - update to 2.1
Storage Copy Data Management - update to 2.2.23.0
Dell EMC VxRail Appliance - update to 8.0.311
Storage Protect Plus Server - update to 10.1.16.1
Dell Secure Connect Gateway - update to 5.12.00.10
watsonx.data - update to 2.1
Storage Copy Data Management - update to 2.2.23.0
Dell EMC VxRail Appliance - update to 8.0.311
Storage Protect Plus Server - update to 10.1.16.1