CVE-2022-28163

CRITICAL

Brocade SANnav < 2.2.0 - SQL Injection via Zone Management Endpoints

Title source: llm
STIX 2.1

Description

In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.

Scores

CVSS v3 9.8
EPSS 0.0037
EPSS Percentile 58.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
broadcom/sannav < 2.2.0
Published May 06, 2022
Tracked Since Feb 18, 2026