CVE-2022-38757

A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside the scope of the administrator. This vulnerability does not result in the administrators gaining additional rights on the managed devices, either in the scope or outside the scope of the administrator.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:zenworks:*:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:update1:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:update2:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:update3:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:update3a:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
References (MISC) https://kmviewer.saas.microfocus.com/#/PH_206720 - Broken Link () https://kmviewer.saas.microfocus.com/#/PH_206720 -
References (MISC) https://portal.microfocus.com/s/article/KM000012895?language=en_US - Vendor Advisory () https://portal.microfocus.com/s/article/KM000012895?language=en_US -
References (MISC) https://kmviewer.saas.microfocus.com/#/PH_206719 - Vendor Advisory () https://kmviewer.saas.microfocus.com/#/PH_206719 -

04 Jan 2023, 18:00

Type Values Removed Values Added
First Time Microfocus
Microfocus zenworks
References (MISC) https://kmviewer.saas.microfocus.com/#/PH_206719 - (MISC) https://kmviewer.saas.microfocus.com/#/PH_206719 - Vendor Advisory
References (MISC) https://portal.microfocus.com/s/article/KM000012895?language=en_US - (MISC) https://portal.microfocus.com/s/article/KM000012895?language=en_US - Vendor Advisory
References (MISC) https://kmviewer.saas.microfocus.com/#/PH_206720 - (MISC) https://kmviewer.saas.microfocus.com/#/PH_206720 - Broken Link
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CPE cpe:2.3:a:microfocus:zenworks:2020:update3:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:update1:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:update3a:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:2020:update2:*:*:*:*:*:*
cpe:2.3:a:microfocus:zenworks:*:*:*:*:*:*:*:*

23 Dec 2022, 16:52

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-23 16:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-38757

Mitre link : CVE-2022-38757

CVE.ORG link : CVE-2022-38757


JSON object : View

Products Affected

microfocus

  • zenworks
CWE
CWE-269

Improper Privilege Management