AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2022-28862

CRITICAL · CVSS 9.8 EPSS 0.99%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-05-25 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2022-28862
Severity
CRITICAL
CVSS
9.8
EPSS
0.99%

Original NVD Description

In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database. This is fixed in all recent versions, such as version 26.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)