Description

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystore is protected with a low-complexity, auto-generated password.

INFO

Published Date :

2025-02-11T00:00:00.000Z

Last Modified :

2025-02-13T17:28:35.378Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2022-35202 vulnerability.

Vendors Products
Sitevision
  • Sitevision

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact