CVE-2022-1065
A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions prior to R4 of 2022-01-15; v2020 versions prior to R6 of 2022-01-15; v2019 versions later than R5 (service pack); v2018 versions later than R5 (service pack). This issue does not affect: Abacus ERP v2019 versions prior to R5 of 2020-03-15; v2018 versions prior to R7 of 2020-04-15; v2017 version and prior versions and prior versions.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 1.63%
- CWE
- CWE-304
- Published
- 2022-04-19
- Last modified
- 2026-03-13
Affected products
- Abacus Research AG Abacus ERP
- Abacus Research AG Abacus ERP
- Abacus Research AG Abacus ERP
- Abacus Research AG Abacus ERP
- Abacus Research AG Abacus ERP
Weakness type
Related vulnerabilities
- CVE-2022-2302 — LENZE: Missing password verification in authorisation procedure
- CVE-2024-8954 — Authentication Bypass in composiohq/composio
- CVE-2022-2821 — Missing Critical Step in Authentication in namelessmc/nameless
- CVE-2024-45764 — Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. A
- CVE-2024-12048 — IDOR Vulnerability in transformeroptimus/superagi
- CVE-2019-16766 — 2FA bypass in Wagtail through new device path
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2024-2172 — Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation