NVD disclosure day

Published threat advisories for February 9, 2022

CVE advisoryKnown Exploit

CVE-2022-22536

SAP Web Dispatcher and NetWeaver Request Smuggling Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Certain SAP products are affected by a vulnerability allowing attackers to prepend arbitrary data to requests. This could lead to impersonation or cache poisoning, potentially resulting in a complete compromise of system confidentiality, integrity, and availability. The business risk is high due to the potential for ex

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-21971

Windows Runtime Remote Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Runtime component of Microsoft Windows systems could allow attackers to execute arbitrary code. This may impact affected organizations by leading to the compromise of systems, data, and business operations. The business risk is present if users interact with malicious content, potentially

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-24682

Zimbra Collaboration Suite: Cross-Site Scripting in Calendar Feature.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An issue in the Calendar feature of Zimbra Collaboration Suite allows attackers to inject executable JavaScript via HTML markup. This could lead to arbitrary markup injection and potential compromise of data. The vulnerability has been actively exploited in the wild. This poses a business risk to organizations using af

• CISA KEV