Show filters
1,713 Total Results
Displaying 361-370 of 1,713
Sort by:
Attacker Value
Unknown

CVE-2022-31593

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Attacker Value
Unknown

CVE-2022-31591

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service
Attacker Value
Unknown

CVE-2022-29619

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.
Attacker Value
Unknown

CVE-2022-28771

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.
Attacker Value
Unknown

CVE-2022-32458

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
Attacker Value
Unknown

CVE-2022-32457

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
Attacker Value
Unknown

CVE-2022-32456

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.
Attacker Value
Unknown

CVE-2022-31784

Disclosure Date: June 17, 2022 (last updated February 23, 2025)
A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A successful exploit could allow arbitrary code execution.
Attacker Value
Unknown

CVE-2022-29093

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.
Attacker Value
Unknown

CVE-2022-29092

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.