CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. See the original NVD description below for full technical details.
CVE
CVE-2022-21939
Severity
HIGH
CVSS
7.5
EPSS
0.55%
Original NVD Description
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Related CVEs
Other vulnerabilities affecting the same vendor(s)