Show filters
709 Total Results
Displaying 91-100 of 709
Sort by:
Attacker Value
Unknown
CVE-2022-34180
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
0
Attacker Value
Unknown
CVE-2022-22967
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.
0
Attacker Value
Unknown
CVE-2017-20066
Disclosure Date: June 20, 2022 (last updated February 23, 2025)
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2022-31589
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2022-27668
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.
0
Attacker Value
Unknown
CVE-2021-35112
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
0
Attacker Value
Unknown
CVE-2022-33174
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
0
Attacker Value
Unknown
CVE-2022-30311
Disclosure Date: June 08, 2022 (last updated February 23, 2025)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown
CVE-2022-30309
Disclosure Date: June 08, 2022 (last updated February 23, 2025)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown
CVE-2022-30310
Disclosure Date: June 08, 2022 (last updated February 23, 2025)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0