CVE-2022-28623

CRITICAL

HPE IceWall SSO 10.0 - SQL Injection

Title source: llm
STIX 2.1

Description

Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd library Patch 9 for HP-UX.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0061
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
hpe/icewall_sso_certd 10.0
Published Jul 08, 2022
Tracked Since Feb 18, 2026