Show filters
46 Total Results
Displaying 1-10 of 46
Sort by:
Attacker Value
Unknown
CVE-2021-22932
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if they previously selected “Enable Encryption” in the ShareFile configuration page and did not re-select this setting after running the CTX269106 mitigation tool. ShareFile customers who have not run the CTX269106 mitigation tool or who re-selected “Enable Encryption” immediately after running the tool are unaffected by this issue.
0
Attacker Value
Unknown
CVE-2021-33900
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
0
Attacker Value
Unknown
CVE-2021-32001
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This issue affects: SUSE Rancher K3s version v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1 and prior versions; RKE2 version v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r1 and prior versions.
0
Attacker Value
Unknown
CVE-2021-22782
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause an information leak allowing disclosure of network and process information, credentials or intellectual property when an attacker can access a project file.
0
Attacker Value
Unknown
CVE-2021-20567
Disclosure Date: June 15, 2021 (last updated February 22, 2025)
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.
0
Attacker Value
Unknown
CVE-2019-4471
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.
0
Attacker Value
Unknown
CVE-2021-29248
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
0
Attacker Value
Unknown
CVE-2020-29024
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.
0
Attacker Value
Unknown
CVE-2020-26732
Disclosure Date: January 14, 2021 (last updated February 22, 2025)
SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
0
Attacker Value
Unknown
CVE-2020-25842
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.
0