Show filters
59 Total Results
Displaying 31-40 of 59
Sort by:
Attacker Value
Unknown

McAfee Network Security Management (NSM) - Password recovery exploitation vulne…

Disclosure Date: June 12, 2018 (last updated November 08, 2023)
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.
0
Attacker Value
Unknown

McAfee Network Security Management (NSM) - Exploitation of Authorization vulner…

Disclosure Date: June 12, 2018 (last updated November 08, 2023)
Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to gain elevated privileges via a crafted HTTP request parameter.
0
Attacker Value
Unknown

SB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulner…

Disclosure Date: May 25, 2018 (last updated November 08, 2023)
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes.
0
Attacker Value
Unknown

CVE-2018-1258

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Attacker Value
Unknown

CVE-2017-1724

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.
0
Attacker Value
Unknown

CVE-2017-1723

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 134812.
0
Attacker Value
Unknown

SB10192 - Network Security Management (NSM) - Cross-Site Request Forgery (CSRF)…

Disclosure Date: April 04, 2018 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.
0
Attacker Value
Unknown

SB10192 - Network Security Management (NSM) - Cryptanalysis vulnerability

Disclosure Date: April 04, 2018 (last updated November 08, 2023)
Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers.
0
Attacker Value
Unknown

SB10192 - Network Security Management (NSM) - Abuse of communication channels v…

Disclosure Date: April 04, 2018 (last updated November 08, 2023)
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL.
0
Attacker Value
Unknown

SB10192 - Network Security Management (NSM) - Exploitation of session variables…

Disclosure Date: April 04, 2018 (last updated November 08, 2023)
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL.
0