Vulnerabilities > CVE-2022-45895 - Exposure of Resource to Wrong Sphere vulnerability in Planetestream Planet Estream

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
planetestream
CWE-668

Summary

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

Vulnerable Configurations

Part Description Count
Application
Planetestream
1

Common Weakness Enumeration (CWE)