Show filters
292 Total Results
Displaying 61-70 of 292
Sort by:
Attacker Value
Unknown

CVE-2022-21940

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Attacker Value
Unknown

CVE-2022-21939

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Attacker Value
Unknown

CVE-2022-21598

Disclosure Date: October 18, 2022 (last updated October 08, 2023)
Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Repository Utilities). Supported versions that are affected are 22.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Attacker Value
Unknown

CVE-2021-35226

Disclosure Date: October 10, 2022 (last updated February 24, 2025)
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.
Attacker Value
Unknown

CVE-2021-39190

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.
Attacker Value
Unknown

CVE-2022-41226

Disclosure Date: September 21, 2022 (last updated February 24, 2025)
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Attacker Value
Unknown

CVE-2022-37972

Disclosure Date: September 20, 2022 (last updated January 11, 2025)
Microsoft Endpoint Configuration Manager Spoofing Vulnerability
Attacker Value
Unknown

CVE-2022-35415

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
An improper input validation in NI System Configuration Manager before 22.5 may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-38007

Disclosure Date: September 13, 2022 (last updated January 11, 2025)
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2022-38772

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.