Show filters
614 Total Results
Displaying 311-320 of 614
Sort by:
Attacker Value
Unknown

CVE-2014-3603

Disclosure Date: April 04, 2019 (last updated November 27, 2024)
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2018-1640

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 144580.
0
Attacker Value
Unknown

CVE-2018-1623

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.
0
Attacker Value
Unknown

CVE-2018-1680

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.
0
Attacker Value
Unknown

CVE-2018-1626

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411.
0
Attacker Value
Unknown

CVE-2018-1625

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 144410.
0
Attacker Value
Unknown

CVE-2018-1622

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144348.
0
Attacker Value
Unknown

CVE-2018-1618

Disclosure Date: April 02, 2019 (last updated November 27, 2024)
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144343.
0
Attacker Value
Unknown

CVE-2019-0222

Disclosure Date: March 28, 2019 (last updated November 08, 2023)
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Attacker Value
Unknown

CVE-2018-20737

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
0