VYPR
High severity8.7NVD Advisory· Published Jun 15, 2022· Updated Jun 17, 2026

CVE-2022-21937

CVE-2022-21937

Description

Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • cpe:2.3:a:johnsoncontrols:metasys_application_and_data_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:johnsoncontrols:metasys_application_and_data_server:*:*:*:*:*:*:*:*range: >=10.0,<=10.1.5
    • cpe:2.3:a:johnsoncontrols:metasys_application_and_data_server:11.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:johnsoncontrols:metasys_application_and_data_server:11.0:*:*:*:*:*:*:*
  • cpe:2.3:a:johnsoncontrols:metasys_extended_application_and_data_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:johnsoncontrols:metasys_extended_application_and_data_server:*:*:*:*:*:*:*:*range: >=10.0,<=10.1.5
    • cpe:2.3:a:johnsoncontrols:metasys_extended_application_and_data_server:11.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:johnsoncontrols:metasys_extended_application_and_data_server:11.0:*:*:*:*:*:*:*
  • cpe:2.3:a:johnsoncontrols:metasys_open_application_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:johnsoncontrols:metasys_open_application_server:*:*:*:*:*:*:*:*range: >=10.0,<10.1.5
    • cpe:2.3:a:johnsoncontrols:metasys_open_application_server:11.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:johnsoncontrols:metasys_open_application_server:11.0:*:*:*:*:*:*:*
  • <10.1.5, <11.0.2+ 1 more
    • (no CPE)range: <10.1.5, <11.0.2
    • (no CPE)range: All 10 versions

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.