Show filters
109 Total Results
Displaying 61-70 of 109
Sort by:
Attacker Value
Unknown

CVE-2019-3670

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote unauthenticated attacker to execute arbitrary code via a cross site scripting attack.
Attacker Value
Unknown

CVE-2019-4672

Disclosure Date: February 24, 2020 (last updated November 27, 2024)
IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 171438.
Attacker Value
Unknown

CVE-2019-4557

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.
Attacker Value
Unknown

CVE-2018-21033

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager and Hitachi Compute Systems Manager.
Attacker Value
Unknown

CVE-2020-7238

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
Attacker Value
Unknown

CVE-2020-2094

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.
Attacker Value
Unknown

CVE-2020-2093

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient.
Attacker Value
Unknown

CVE-2019-18582

Disclosure Date: December 06, 2019 (last updated February 21, 2025)
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject malicious report generation scripts in the server. This may lead to OS command execution as the regular user runs the DPA service on the affected system.
Attacker Value
Unknown

CVE-2019-18581

Disclosure Date: December 06, 2019 (last updated February 21, 2025)
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.
Attacker Value
Unknown

API Abuse Vulnerability

Disclosure Date: December 03, 2019 (last updated November 08, 2023)
API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site.