CVE-2022-22795 - CVE House
Back to Database
Status published Medium CVE-2022-22795

Signiant - Manager+Agents XML External Entity (XXE)

Vulnerability Description

Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file on the systems, such as passwd, shadow, hosts and so on. By gaining access to these files, attackers can steal sensitive information from the victims machine.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22795

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Anton Golotin

Affected Vendor

Affected Software

Signiant
Vulnerable Versions:
Signiant Build 78045 13.5.0, Signiant Build 79008,14.0.0, Signiant Build 79687 14.1.0, Signiant Build 79687 15.0.0

Timeline

Official Publish: March 9th, 2022
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Weaknesses (CWE)