CVE-2022-47551

MEDIUM

apiman 1.5.7-2.2.3.Final - Unauthenticated Permission Bypass via Manager REST API

Title source: llm
STIX 2.1

Description

Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatible with the security model of Apiman versions before 3.0.0.Final. Because of this, 3.0.0.Final is not affected by the vulnerability.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0060
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (2)
apiman/apiman 1.5.7 - 2.2.3
io.apiman/apiman-manager-api-rest-impl 1.5.7 - 3.0.0.FinalMaven
Published Dec 20, 2022
Tracked Since Feb 18, 2026