Show filters
1,711 Total Results
Displaying 191-200 of 1,711
Sort by:
Attacker Value
Unknown
CVE-2023-22082
Disclosure Date: October 17, 2023 (last updated October 26, 2023)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown
CVE-2023-22076
Disclosure Date: October 17, 2023 (last updated October 24, 2023)
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown
CVE-2023-35024
Disclosure Date: October 14, 2023 (last updated February 25, 2025)
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 258349.
0
Attacker Value
Unknown
CVE-2023-41763
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2023-36789
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-36786
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-36780
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-42474
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.
0
Attacker Value
Unknown
CVE-2023-41365
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.
0
Attacker Value
Unknown
CVE-2023-20268
Disclosure Date: September 27, 2023 (last updated February 25, 2025)
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.
This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A sustained attack could lead to the disruption of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel and intermittent loss of wireless client traffic.
0