Show filters
83 Total Results
Displaying 61-70 of 83
Sort by:
Attacker Value
Unknown
CVE-2020-13168
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
0
Attacker Value
Unknown
CVE-2020-4607
Disclosure Date: September 28, 2020 (last updated February 22, 2025)
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.
0
Attacker Value
Unknown
CVE-2020-10569
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This may be a duplicate of CVE-2020-1938
0
Attacker Value
Unknown
CVE-2019-4446
Disclosure Date: April 16, 2020 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
0
Attacker Value
Unknown
CVE-2019-14221
Disclosure Date: August 08, 2019 (last updated November 27, 2024)
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
0
Attacker Value
Unknown
CVE-2017-14935
Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive information.
0
Attacker Value
Unknown
CVE-2017-4978
Disclosure Date: May 19, 2017 (last updated November 26, 2024)
EMC RSA Adaptive Authentication (On-Premise) versions prior to 7.3 P2 (exclusive) contains a fix for a cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.
0
Attacker Value
Unknown
CVE-2016-0925
Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Case Management application in EMC RSA Adaptive Authentication (On-Premise) before 6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and 7.2.x before 7.2.0.0.SP0.P0 HF20 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-4631
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.
0
Attacker Value
Unknown
CVE-2014-7169
Disclosure Date: September 25, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
0