s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2022-0020 medium

📛 Threat Title

Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface

Category: vulnerability Published: Source updated: First seen: Last updated: Source: Paloalto Networks Security

Description

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will per...

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2022-0020

IOC database

Type
cve
Value
CVE-2022-0020
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • Palo Alto Networks advisory: CVE-2022-0020 Paloalto Networks Security

    A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will per...

Remediations (8)

  • web:federalnewsnetwork.com

    CISA this year has already started accelerating the deadlines for agencies to patch software bugs posted to the Known Exploited Vulnerabilities (KEV) catalog.

  • web:portal.msrc.microsoft.com

    The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

  • web:www.bleepingcomputer.com

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their Windows systems against a vulnerability exploited in zero-day attacks.

  • web:www.cisa.gov

    CISA has added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

  • web:www.malwarebytes.com

    Run Windows Update today, restart your PC, and check you're up to date. What's been fixed Microsoft releases important security updates on the second Tuesday of every month—known as " Patch Tuesday." This month's patches fix critical flaws in Windows 10, Windows 11, Windows Server, Office, and related services.

  • web:www.oracle.com

    This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

  • web:www.pcworld.com

    This month's Patch Tuesday includes an actively exploited Office zero-day vulnerability and several critical RCE bugs in Windows and Remote Desktop.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.