Show filters
146 Total Results
Displaying 71-80 of 146
Sort by:
Attacker Value
Unknown

CVE-2018-18980

Disclosure Date: November 06, 2018 (last updated November 27, 2024)
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
0
Attacker Value
Unknown

CVE-2018-17051

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
0
Attacker Value
Unknown

CVE-2018-7077

Disclosure Date: August 14, 2018 (last updated November 27, 2024)
A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), Configuration Manager (CM 8.5.0-00 and prior to 8.6.0-00) could be exploited to allow local and remote unauthorized access to sensitive information.
0
Attacker Value
Unknown

CVE-2018-12997

Disclosure Date: June 29, 2018 (last updated December 08, 2023)
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server without login by sending a specially crafted request to the server with the operation=copyfile&fileName= substring.
Attacker Value
Unknown

CVE-2018-12998

Disclosure Date: June 29, 2018 (last updated December 08, 2023)
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
Attacker Value
Unknown

MFSBGN03803 rev.1 - UCMDB, Installation File Access Control Privilege Escalatio…

Disclosure Date: April 24, 2018 (last updated November 08, 2023)
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
0
Attacker Value
Unknown

CVE-2015-5016

Disclosure Date: March 27, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
0
Attacker Value
Unknown

MFSBGN03798 rev.1 - Micro Focus Universal CMDB, Apache Struts Instance

Disclosure Date: February 22, 2018 (last updated November 08, 2023)
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.
0
Attacker Value
Unknown

CVE-2017-8947

Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.
0
Attacker Value
Unknown

CVE-2017-8017

Disclosure Date: October 11, 2017 (last updated November 26, 2024)
EMC Network Configuration Manager (NCM) 9.3.x, 9.4.0.x, 9.4.1.x, and 9.4.2.x is affected by a reflected cross-site scripting Vulnerability that could potentially be exploited by malicious users to compromise the affected system.
0