Show filters
91 Total Results
Displaying 11-20 of 91
Sort by:
Attacker Value
Unknown
CVE-2024-53247
Disclosure Date: December 10, 2024 (last updated January 07, 2025)
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE).
0
Attacker Value
Unknown
CVE-2024-53243
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could see alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints due to improper access control.
0
Attacker Value
Unknown
CVE-2024-45164
Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.
0
Attacker Value
Unknown
CVE-2023-28872
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.
0
Attacker Value
Unknown
CVE-2023-28871
Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
0
Attacker Value
Unknown
CVE-2023-28870
Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
0
Attacker Value
Unknown
CVE-2023-28869
Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.
0
Attacker Value
Unknown
CVE-2023-28868
Disclosure Date: December 09, 2023 (last updated December 13, 2023)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.
0
Attacker Value
Unknown
CVE-2022-2764
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
0
Attacker Value
Unknown
CVE-2022-1259
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
0