Show filters
255 Total Results
Displaying 71-80 of 255
Sort by:
Attacker Value
Unknown

ACM SQL Injection

Disclosure Date: July 11, 2019 (last updated November 27, 2024)
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.
Attacker Value
Unknown

CVE-2018-10512

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, which may lead to a denial of server (DoS).
0
Attacker Value
Unknown

CVE-2018-10510

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.
0
Attacker Value
Unknown

CVE-2018-10511

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.
Attacker Value
Unknown

CVE-2013-5461

Disclosure Date: April 27, 2018 (last updated November 26, 2024)
IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.
0
Attacker Value
Unknown

CVE-2015-4952

Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. IBM X-Force ID: 105196.
0
Attacker Value
Unknown

CVE-2015-5016

Disclosure Date: March 27, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
0
Attacker Value
Unknown

CVE-2017-1758

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.
0
Attacker Value
Unknown

CVE-2017-5787

Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 was found.
0
Attacker Value
Unknown

CVE-2016-8514

Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.
0