Show filters
273 Total Results
Displaying 21-30 of 273
Sort by:
Attacker Value
Unknown
CVE-2023-6911
Disclosure Date: December 18, 2023 (last updated December 23, 2023)
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
0
Attacker Value
Unknown
CVE-2023-6838
Disclosure Date: December 15, 2023 (last updated December 20, 2023)
Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
0
Attacker Value
Unknown
CVE-2023-6837
Disclosure Date: December 15, 2023 (last updated January 04, 2025)
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met:
* An IDP configured for federated authentication and JIT provisioning enabled with the "Prompt for username, password and consent" option.
* A service provider that uses the above IDP for federated authentication and has the "Assert identity using mapped local subject identifier" flag enabled.
Attacker should have:
* A fresh valid user account in the federated IDP that has not been used earlier.
* Knowledge of the username of a valid user in the local IDP.
When all preconditions are met, a malicious actor could use JIT provisioning flow to perform user impersonation.
0
Attacker Value
Unknown
CVE-2023-6836
Disclosure Date: December 15, 2023 (last updated December 20, 2023)
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
0
Attacker Value
Unknown
CVE-2023-20884
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2023-20121
Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.
0
Attacker Value
Unknown
CVE-2023-23951
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
0
Attacker Value
Unknown
CVE-2023-23950
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
0
Attacker Value
Unknown
CVE-2023-23949
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
0
Attacker Value
Unknown
CVE-2022-26329
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL.
0