Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2022-34125

Disclosure Date: April 16, 2023 (last updated October 08, 2023)
front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.
Attacker Value
Unknown

CVE-2022-1399

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.
Attacker Value
Unknown

CVE-2022-1400

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.
Attacker Value
Unknown

CVE-2022-1410

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions.
Attacker Value
Unknown

CVE-2022-1401

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.
Attacker Value
Unknown

CVE-2022-25518

Disclosure Date: March 22, 2022 (last updated February 23, 2025)
In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the database table.
Attacker Value
Unknown

MFSBGN03838 rev.1 - UCMDB Configuration Management Service, Multiple Vulnerabil…

Disclosure Date: December 31, 2018 (last updated November 08, 2023)
Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities could allow Remote Directory Traversal and Remote Disclosure of Privileged Information
0
Attacker Value
Unknown

MFSBGN03808 rev.1 - Micro Focus UCMDB, Cross-Site Scripting

Disclosure Date: May 23, 2018 (last updated November 08, 2023)
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
Attacker Value
Unknown

MFSBGN03803 rev.1 - UCMDB, Installation File Access Control Privilege Escalatio…

Disclosure Date: April 24, 2018 (last updated November 08, 2023)
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
0
Attacker Value
Unknown

MFSBGN03798 rev.1 - Micro Focus Universal CMDB, Apache Struts Instance

Disclosure Date: February 22, 2018 (last updated November 08, 2023)
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.
0