CVE-2022-35202

MEDIUM EPSS 15.1%
Published Feb 11, 20251y ago · Modified Jun 17, 20262w ago
5.1 CVSS 3.1
Medium
Find Similar
Published Feb 11, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystore is protected with a low-complexity, auto-generated password.

CVSS Details

Base Score
5.1
Exploitability
2.5
Impact
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
15.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-532

References 2

  • developer.sitevision.se https://developer.sitevision.se/archives/release-notes/release-notes/2022-05-06-release-notes-sitevision-10.3
  • shelltrail.com https://www.shelltrail.com/research/how-auto-generated-passwords-in-sitevision-leads-to-signing-key-leakage-cve-2022-35202/

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.