Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2019-10449

Disclosure Date: October 16, 2019 (last updated October 26, 2023)
Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Attacker Value
Unknown

KM03461174 Micro Focus Fortify Software Security Center Server, CVE-2019-11649

Disclosure Date: June 19, 2019 (last updated November 08, 2023)
Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to execute JavaScript code in user’s browser. The vulnerability could be exploited to execute JavaScript code in user’s browser.
0
Attacker Value
Unknown

CVE-2019-1003046

Disclosure Date: March 28, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown

CVE-2019-1003047

Disclosure Date: March 28, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Attacker Value
Unknown

MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized…

Disclosure Date: December 13, 2018 (last updated November 08, 2023)
A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access
0
Attacker Value
Unknown

MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized…

Disclosure Date: December 13, 2018 (last updated November 08, 2023)
A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access
0
Attacker Value
Unknown

MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabil…

Disclosure Date: July 12, 2018 (last updated November 08, 2023)
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Attacker Value
Unknown

CVE-2018-1000607

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to control rulepack zip file contents to overwrite any file on the Jenkins master file system, only limited by the permissions of the user the Jenkins master process is running as.
0
Attacker Value
Unknown

CVE-2018-6486

Disclosure Date: February 01, 2018 (last updated November 08, 2023)
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.
0
Attacker Value
Unknown

CVE-2012-3248

Disclosure Date: August 16, 2012 (last updated October 04, 2023)
HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote attackers to obtain sensitive information via unspecified vectors.
0