PT-2022-19874 · Ipswitch · Ipswitch Whatsup Gold

Published

2022-05-11

·

Updated

2024-08-27

·

CVE-2022-29848

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ipswitch WhatsUp Gold versions 17.0.0 through 21.1.1 Ipswitch WhatsUp Gold version 22.0.0
Description The issue allows an authenticated user to invoke an API transaction to read sensitive operating-system attributes from a host accessible by the WhatsUp Gold system.
Recommendations For Ipswitch WhatsUp Gold versions 17.0.0 through 21.1.1, consider restricting access to the API transaction until a patch is available. For Ipswitch WhatsUp Gold version 22.0.0, consider restricting access to the API transaction until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-29848

Affected Products

Ipswitch Whatsup Gold