Show filters
1,713 Total Results
Displaying 511-520 of 1,713
Sort by:
Attacker Value
Unknown
CVE-2021-1574
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific features and for access to log files that contain confidential information. An attacker could exploit these vulnerabilities either by submitting crafted HTTP messages to an affected system and performing unauthorized actions with the privileges of an administrator, or by retrieving sensitive data from the logs and using it to impersonate a legitimate privileged user. A successful exploit could allow the attacker to elevate privileges to Administrator.
0
Attacker Value
Unknown
CVE-2021-34427
Disclosure Date: June 25, 2021 (last updated February 22, 2025)
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.
0
Attacker Value
Unknown
CVE-2021-29775
Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203029.
0
Attacker Value
Unknown
CVE-2021-29751
Disclosure Date: June 25, 2021 (last updated November 28, 2024)
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.
0
Attacker Value
Unknown
CVE-2021-20742
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.
0
Attacker Value
Unknown
CVE-2021-20744
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
0
Attacker Value
Unknown
CVE-2021-30468
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
0
Attacker Value
Unknown
CVE-2021-0054
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2021-0067
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2021-33662
Disclosure Date: June 09, 2021 (last updated November 28, 2024)
Under certain conditions, the installation of SAP Business One, version - 10.0, discloses sensitive information on the file system allowing an attacker to access information which would otherwise be restricted.
0