Show filters
561 Total Results
Displaying 11-20 of 561
Sort by:
Attacker Value
Unknown

CVE-2025-24504

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
0
Attacker Value
Unknown

CVE-2025-24503

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
0
Attacker Value
Unknown

CVE-2025-24502

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
0
Attacker Value
Unknown

CVE-2025-24501

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.
0
Attacker Value
Unknown

CVE-2025-24500

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
The vulnerability allows an unauthenticated attacker to access information in PAM database.
0
Attacker Value
Unknown

CVE-2024-38499

Disclosure Date: December 17, 2024 (last updated December 18, 2024)
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.
0
Attacker Value
Unknown

CVE-2024-10403

Disclosure Date: November 21, 2024 (last updated February 05, 2025)
Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.
Attacker Value
Unknown

CVE-2022-43937

Disclosure Date: November 21, 2024 (last updated February 05, 2025)
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a
Attacker Value
Unknown

CVE-2022-43936

Disclosure Date: November 21, 2024 (last updated February 05, 2025)
Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
Attacker Value
Unknown

CVE-2022-43935

Disclosure Date: November 21, 2024 (last updated February 05, 2025)
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are printed in the embedded MLS DB file.