Show filters
1,711 Total Results
Displaying 121-130 of 1,711
Sort by:
Attacker Value
Unknown

CVE-2024-31897

Disclosure Date: July 08, 2024 (last updated February 26, 2025)
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 288178.
Attacker Value
Unknown

CVE-2024-28984

Disclosure Date: June 26, 2024 (last updated February 26, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
Attacker Value
Unknown

CVE-2024-28983

Disclosure Date: June 26, 2024 (last updated February 26, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
Attacker Value
Unknown

CVE-2024-28982

Disclosure Date: June 26, 2024 (last updated February 26, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
Attacker Value
Unknown

CVE-2024-5683

Disclosure Date: June 24, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Remote Code Inclusion.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
0
Attacker Value
Unknown

CVE-2024-4754

Disclosure Date: June 24, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
0
Attacker Value
Unknown

CVE-2024-2003

Disclosure Date: June 21, 2024 (last updated February 26, 2025)
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
0
Attacker Value
Unknown

CVE-2024-34024

Disclosure Date: June 18, 2024 (last updated June 18, 2024)
Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine if a username is valid or not.
0
Attacker Value
Unknown

CVE-2024-33622

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be obtained and/or the information stored in the database may be altered by a remote authenticated attacker.
0
Attacker Value
Unknown

CVE-2024-33620

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.
0