Show filters
91 Total Results
Displaying 11-20 of 91
Sort by:
Attacker Value
Unknown

CVE-2024-53247

Disclosure Date: December 10, 2024 (last updated January 07, 2025)
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE).
0
Attacker Value
Unknown

CVE-2024-53243

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could see alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints due to improper access control.
0
Attacker Value
Unknown

CVE-2024-45164

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
Attacker Value
Unknown

CVE-2023-28872

Disclosure Date: December 25, 2023 (last updated January 04, 2024)
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.
Attacker Value
Unknown

CVE-2023-28871

Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
Attacker Value
Unknown

CVE-2023-28870

Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
Attacker Value
Unknown

CVE-2023-28869

Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.
Attacker Value
Unknown

CVE-2023-28868

Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.
Attacker Value
Unknown

CVE-2022-2764

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
Attacker Value
Unknown

CVE-2022-1259

Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.