Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andreas Vikerup

#48611of 53,639
5.1Total CVSS
Vulnerabilities · 1
PT-2025-6375
5.1
2025-02-11
Unknown · Sitevision · CVE-2022-35202
**Name of the Vulnerable Software and Affected Versions** Sitevision versions 10.3.1 and earlier **Description** A security issue in Sitevision allows a remote attacker, in certain non-default scenarios, to gain access to the private keys used for signing SAML authentication requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystore is protected with a low-complexity, auto-generated password. **Recommendations** For Sitevision versions 10.3.1 and earlier, consider disabling WebDAV access to the Java keystore as a temporary workaround until a patch is available. Restrict access to the keystore to minimize the risk of exploitation. Avoid using auto-generated passwords for the keystore. At the moment, there is no information about a newer version that contains a fix for this vulnerability.