CVE-2022-38482

CVSS v3 Score
4.3
Medium

Vulnerability Description

A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.

CVSS:4.3(Medium)

IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:/...

CWE-592020
CVSS:4.3(Medium)

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a symlink following bug al...

CWE-592022
CVSS:4.3(Medium)

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.

CWE-592023
CVSS:4.4(Medium)

Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restri...

CWE-592018
CVSS:4.4(Medium)

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to wr...

CWE-592019
CVSS:4.4(Medium)

IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.

CWE-592020