#VU62486 Missing Authentication for Critical Function in AssetView - CVE-2022-28719
Published: April 22, 2022
AssetView
Hammock Corporation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication for some critical functions on the managing server. A remote attacker can upload a specially crafted configuration file to the managing server and execute arbitrary code with the administrative privilege.