Show filters
538 Total Results
Displaying 211-220 of 538
Sort by:
Attacker Value
Unknown
CVE-2021-35244
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
0
Attacker Value
Unknown
CVE-2021-45105
Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
0
Attacker Value
Unknown
CVE-2021-44427
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.
0
Attacker Value
Unknown
CVE-2021-35665
Disclosure Date: October 20, 2021 (last updated November 28, 2024)
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hyperion Financial Reporting, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown
CVE-2021-41061
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.
0
Attacker Value
Unknown
CVE-2021-35213
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication is required to exploit the vulnerability.
0
Attacker Value
Unknown
CVE-2021-35218
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server
0
Attacker Value
Unknown
CVE-2021-35238
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
0
Attacker Value
Unknown
CVE-2021-35212
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.
0
Attacker Value
Unknown
CVE-2021-35239
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
0