Show filters
62 Total Results
Displaying 41-50 of 62
Sort by:
Attacker Value
Unknown

CVE-2020-15771

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.
Attacker Value
Unknown

CVE-2020-2239

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2020-2249

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2020-2250

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2020-4591

Disclosure Date: August 28, 2020 (last updated February 22, 2025)
IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.
Attacker Value
Unknown

CVE-2019-4686

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171822.
Attacker Value
Unknown

CVE-2020-3389

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists because sensitive information is stored as clear text. An attacker could exploit this vulnerability by authenticating to an affected device and navigating to the directory that contains sensitive information. A successful exploit could allow the attacker to obtain sensitive information in clear text from the affected device.
Attacker Value
Unknown

CVE-2020-9062

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal ATM components to commit deposit forgery by intercepting and modifying messages to the host computer, such as the amount and value of currency being deposited.
Attacker Value
Unknown

CVE-2020-10124

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.
Attacker Value
Unknown

CVE-2020-10039

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker in a privileged network position between a legitimate user and the web server might be able to conduct a Man-in-the-middle attack and gain read and write access to the transmitted data.