Vulnerability record · CVE-2022-2457 · published 10 August 2022
CVE-2022-2457: Redhat process automation manager improper restriction of authentication attempts vulnerability
Redhat · Process Automation Manager
A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.
Description
A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2107990#c0 | Issue TrackingVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2107990#c0 | Issue TrackingVendor Advisory |
Track CVE-2022-2457 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2457), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.