Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2024-45164

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
Attacker Value
Unknown

CVE-2021-40683

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
Attacker Value
Unknown

CVE-2019-18847

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
Attacker Value
Unknown

CVE-2019-11011

Disclosure Date: June 21, 2019 (last updated November 27, 2024)
Akamai CloudTest before 58.30 allows remote code execution.
0
Attacker Value
Unknown

CVE-2016-10157

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code within the Akamai NetSession process space.
0
Attacker Value
Unknown

CVE-2009-2582

Disclosure Date: July 23, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a Redswoosh download, a different vulnerability than CVE-2007-1891 and CVE-2007-1892.
0
Attacker Value
Unknown

CVE-2008-1106

Disclosure Date: June 09, 2008 (last updated October 04, 2023)
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.
0
Attacker Value
Unknown

CVE-2008-1770

Disclosure Date: June 04, 2008 (last updated October 04, 2023)
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.
0
Attacker Value
Unknown

CVE-2007-6339

Disclosure Date: May 01, 2008 (last updated October 04, 2023)
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified "undocumented object parameters."
0
Attacker Value
Unknown

CVE-2007-1892

Disclosure Date: April 18, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2007-1891.
0