Show filters
1,202 Total Results
Displaying 161-170 of 1,202
Sort by:
Attacker Value
Unknown
CVE-2022-21936
Disclosure Date: October 04, 2022 (last updated February 24, 2025)
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
0
Attacker Value
Unknown
CVE-2022-35282
Disclosure Date: September 27, 2022 (last updated February 24, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.
0
Attacker Value
Unknown
CVE-2022-39799
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
0
Attacker Value
Unknown
CVE-2022-35294
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.
0
Attacker Value
Unknown
CVE-2022-34336
Disclosure Date: September 12, 2022 (last updated February 24, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.
0
Attacker Value
Unknown
CVE-2022-34165
Disclosure Date: September 07, 2022 (last updated February 24, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.
0
Attacker Value
Unknown
CVE-2021-36200
Disclosure Date: July 21, 2022 (last updated February 24, 2025)
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
0
Attacker Value
Unknown
CVE-2022-22473
Disclosure Date: July 13, 2022 (last updated October 07, 2023)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
0
Attacker Value
Unknown
CVE-2022-22477
Disclosure Date: July 13, 2022 (last updated February 24, 2025)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
0
Attacker Value
Unknown
CVE-2022-22476
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
0