Configuration in Red Hat Single Sign-On - CVE-2022-4039

 

Configuration in Red Hat Single Sign-On - CVE-2022-4039

Published: March 2, 2023


Vulnerability identifier: #VU72726
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4039
CWE-ID: CWE-16
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to Keycloak instances launched by the Operator are configured with an unsecured management interface enabled. A remote attacker on the local network can use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.


Affected software

Red Hat Single Sign-On

How to mitigate CVE-2022-4039

Install updates from vendor's website.

Red Hat Single Sign-On - update to 7.6.2

External References

Related Security Bulletins