CVE-2022-42711
WhatsUp Gold vulnerability analysis and mitigation

Overview

CVE-2022-42711 affects Progress WhatsUp Gold versions prior to 22.1.0. The vulnerability involves an SNMP MIB Walker application endpoint that failed to adequately sanitize malicious input, potentially leading to Cross-Site Scripting (XSS) attacks (NVD, Progress Community).

Technical details

The vulnerability is identified as a Cross-Site Scripting (XSS) issue in the SNMP MIB Walker application endpoint of WhatsUp Gold. The core issue stems from inadequate input sanitization in the application endpoint, which could allow malicious input to be processed (Progress Community).

Impact

The vulnerability could potentially allow attackers to execute malicious cross-site scripting attacks through the affected SNMP MIB Walker application endpoint (NVD).

Mitigation and workarounds

Users are advised to upgrade to WhatsUp Gold version 22.1.0 or later to address this vulnerability (Progress Community).

Additional resources


SourceThis report was generated using AI

Related WhatsUp Gold vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-12108CRITICAL9.6
  • WhatsUp GoldWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesDec 31, 2024
CVE-2024-12106HIGH7.5
  • WhatsUp GoldWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesDec 31, 2024
CVE-2024-12105MEDIUM6.5
  • WhatsUp GoldWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesDec 31, 2024
CVE-2025-2572MEDIUM5.3
  • WhatsUp GoldWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesApr 14, 2025
CVE-2024-8785MEDIUM5.3
  • WhatsUp GoldWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesDec 02, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management