Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2022-25027
Disclosure Date: January 12, 2023 (last updated October 08, 2023)
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
0
Attacker Value
Unknown
CVE-2022-25026
Disclosure Date: January 12, 2023 (last updated October 08, 2023)
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
0
Attacker Value
Unknown
CVE-2022-36431
Disclosure Date: December 01, 2022 (last updated October 08, 2023)
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
0
Attacker Value
Unknown
CVE-2021-45026
Disclosure Date: June 17, 2022 (last updated October 07, 2023)
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2021-45025
Disclosure Date: June 17, 2022 (last updated October 07, 2023)
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
0
Attacker Value
Unknown
CVE-2021-45024
Disclosure Date: June 17, 2022 (last updated October 07, 2023)
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
0
Attacker Value
Unknown
CVE-2014-3914
Disclosure Date: August 07, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a .. (dot dot) in the query parameter in a writeDataFile action to the fileRequestor servlet, execute arbitrary files via a .. (dot dot) in the query parameter in a (2) run or (3) runClear action to the fileRequestor servlet, (4) read arbitrary files via a readDataFile action to the fileRequestor servlet, (5) execute arbitrary code via a save_server_groups action to the userRequest servlet, or (6) delete arbitrary files via a del action in the fileRequestServlet servlet.
0
Attacker Value
Unknown
CVE-2014-3915
Disclosure Date: June 11, 2014 (last updated October 05, 2023)
The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) auth_session, (3) auth_simple, (4) add, (5) add_flat, (6) remove, (7) set_pwd, (8) add_permissions, (9) revoke_permissions, (10) runAsync, or (11) tsmRequest command.
0