CVE-2022-45166
Description
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A low-privileged user in Archibus Web Central 2022.03.01.107 can access data outside their role via a service that accepts user-controlled parameters.
Vulnerability
Archibus Web Central version 2022.03.01.107 exposes a service that accepts user-controlled parameters to act on returned data. This design flaw allows a basic user to access data unrelated to their role. The vulnerability does not require any special configuration beyond having a valid low-privileged account.
Exploitation
An attacker needs only a basic, authenticated user account on the affected Archibus Web Central instance. No special privileges, network position, or user interaction is required. By manipulating the user-controlled parameters supplied to the exposed service, the attacker can retrieve data that should be restricted to other roles.
Impact
Successful exploitation results in unauthorized disclosure of sensitive information (confidentiality breach). The CVSS vector indicates a HIGH confidentiality impact with no impact on integrity or availability. The attacker gains access to data that is not intended for their assigned role but does not obtain elevated privileges (e.g., administrative rights).
Mitigation
As of the published advisory date (30 November 2022), no patches or official fixes were available from the vendor [1][2]. The vendor was notified on multiple occasions starting 29 July 2022, but no fix has been released. No workarounds are documented in the available references. Administrators should monitor vendor updates for a future patch.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Archibus/Web Centraldescription
- Range: =2022.03.01.107
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.