CVE-2022-38757 - CVE House
Back to Database
Status published High CVE-2022-38757

CVE-2022-38757 ZENworks

Vulnerability Description

A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside the scope of the administrator. This vulnerability does not result in the administrators gaining additional rights on the managed devices, either in the scope or outside the scope of the administrator.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-38757

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Micro Focus

View all reports →

Affected Software

ZENworks Configuration Management (ZCM), ZENworks Asset Management, ZENworks Endpoint Security Management (ZESM), ZENworks Patch Management (ZPM)
Vulnerable Versions:
ZENworks 2020

Timeline

Official Publish: December 23rd, 2022
Last Modified: April 15th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)