Show filters
171 Total Results
Displaying 71-80 of 171
Sort by:
Attacker Value
Unknown

CVE-2021-29759

Disclosure Date: July 06, 2021 (last updated February 23, 2025)
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, and 1.3 could allow a privileged user to obtain sensitive information from internal log files. IBM X-Force ID: 202212.
Attacker Value
Unknown

CVE-2021-33669

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality integrity and availability.
Attacker Value
Unknown

CVE-2018-10868

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.
Attacker Value
Unknown

CVE-2018-10865

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
Attacker Value
Unknown

CVE-2018-10867

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.
Attacker Value
Unknown

CVE-2018-10863

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
Attacker Value
Unknown

CVE-2018-10866

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him.
Attacker Value
Unknown

CVE-2019-3897

Disclosure Date: March 16, 2021 (last updated February 22, 2025)
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue.
Attacker Value
Unknown

CVE-2021-20179

Disclosure Date: March 15, 2021 (last updated February 22, 2025)
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Attacker Value
Unknown

CVE-2021-26713

Disclosure Date: February 19, 2021 (last updated February 22, 2025)
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession. This is caused by a signedness comparison mismatch.