Show filters
39 Total Results
Displaying 11-20 of 39
Sort by:
Attacker Value
Unknown
CVE-2023-26211
Disclosure Date: August 13, 2024 (last updated August 23, 2024)
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
0
Attacker Value
Unknown
CVE-2024-38319
Disclosure Date: June 22, 2024 (last updated June 23, 2024)
IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.
0
Attacker Value
Unknown
CVE-2023-23775
Disclosure Date: June 11, 2024 (last updated January 22, 2025)
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
0
Attacker Value
Unknown
CVE-2024-31493
Disclosure Date: June 03, 2024 (last updated January 22, 2025)
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
0
Attacker Value
Unknown
CVE-2023-38263
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577.
0
Attacker Value
Unknown
CVE-2023-38020
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.
0
Attacker Value
Unknown
CVE-2023-38019
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.
0
Attacker Value
Unknown
CVE-2023-3282
Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.
0
Attacker Value
Unknown
CVE-2023-3997
Disclosure Date: July 31, 2023 (last updated December 10, 2024)
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.
0
Attacker Value
Unknown
CVE-2023-27995
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
0