Show filters
245 Total Results
Displaying 31-40 of 245
Sort by:
Attacker Value
Unknown

CVE-2021-3809

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
Attacker Value
Unknown

CVE-2021-3808

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
Attacker Value
Unknown

CVE-2021-3439

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.
Attacker Value
Unknown

CVE-2022-28884

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.
Attacker Value
Unknown

CVE-2022-32458

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
Attacker Value
Unknown

CVE-2022-32457

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
Attacker Value
Unknown

CVE-2022-32456

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.
Attacker Value
Unknown

CVE-2022-22361

Disclosure Date: May 27, 2022 (last updated February 23, 2025)
IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0 through 8.6.0.201803, and 8.5.0.0 through 8.5.0.201706 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Attacker Value
Unknown

CVE-2021-39298

Disclosure Date: May 10, 2022 (last updated November 08, 2023)
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
Attacker Value
Unknown

CVE-2019-14839

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.