VYPR
Unrated severityNVD Advisory· Published Jan 10, 2023· Updated May 30, 2025

CVE-2022-45166

CVE-2022-45166

Description

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A low-privileged user in Archibus Web Central 2022.03.01.107 can access data outside their role via a service that accepts user-controlled parameters.

Vulnerability

Archibus Web Central version 2022.03.01.107 exposes a service that accepts user-controlled parameters to act on returned data. This design flaw allows a basic user to access data unrelated to their role. The vulnerability does not require any special configuration beyond having a valid low-privileged account.

Exploitation

An attacker needs only a basic, authenticated user account on the affected Archibus Web Central instance. No special privileges, network position, or user interaction is required. By manipulating the user-controlled parameters supplied to the exposed service, the attacker can retrieve data that should be restricted to other roles.

Impact

Successful exploitation results in unauthorized disclosure of sensitive information (confidentiality breach). The CVSS vector indicates a HIGH confidentiality impact with no impact on integrity or availability. The attacker gains access to data that is not intended for their assigned role but does not obtain elevated privileges (e.g., administrative rights).

Mitigation

As of the published advisory date (30 November 2022), no patches or official fixes were available from the vendor [1][2]. The vendor was notified on multiple occasions starting 29 July 2022, but no fix has been released. No workarounds are documented in the available references. Administrators should monitor vendor updates for a future patch.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.