← Voltar para CVEs
CVE-2022-37400
HIGH8.8
Descricao
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26306 - LibreOffice
Detalhes CVE
Pontuacao CVSS v3.18.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado8/15/2022
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
apache:openoffice
Fraquezas (CWE)
CWE-330CWE-330
Referencias
http://www.openwall.com/lists/oss-security/2022/08/13/1(security@apache.org)
https://www.openoffice.org/security/cves/CVE-2022-37400.html(security@apache.org)
http://www.openwall.com/lists/oss-security/2022/08/13/1(af854a3a-2127-422b-91ae-364da2661108)
https://www.openoffice.org/security/cves/CVE-2022-37400.html(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.