SB2022060112 - Insufficient Session Expiration in BD Synapsys



SB2022060112 - Insufficient Session Expiration in BD Synapsys

Published: June 1, 2022

Security Bulletin ID SB2022060112
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient Session Expiration (CVE-ID: CVE-2022-30277)

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to insufficient session expiration issue. An authenticated attacker with physical access can gain access to sensitive information and modificate ePHI, PHI, or PII.


Remediation

Install update from vendor's website.