Show filters
45 Total Results
Displaying 1-10 of 45
Sort by:
Attacker Value
Unknown
CVE-2025-22510
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Deserialization of Untrusted Data vulnerability in Konrad Karpieszuk WC Price History for Omnibus allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through 2.1.4.
0
Attacker Value
Unknown
CVE-2024-12617
Disclosure Date: December 24, 2024 (last updated January 05, 2025)
The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and modify history data.
0
Attacker Value
Unknown
CVE-2023-48645
Disclosure Date: February 02, 2024 (last updated February 26, 2025)
An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in the Maintenance module of the app. This allows performing queries on the local database.
0
Attacker Value
Unknown
CVE-2022-45167
Disclosure Date: January 10, 2023 (last updated February 24, 2025)
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to access the profile information of all connected users.
0
Attacker Value
Unknown
CVE-2022-45166
Disclosure Date: January 10, 2023 (last updated February 24, 2025)
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role.
0
Attacker Value
Unknown
CVE-2022-45164
Disclosure Date: January 10, 2023 (last updated February 24, 2025)
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to cancel (delete) a booking, created by someone else - even if this basic user is not a member of the booking
0
Attacker Value
Unknown
CVE-2021-29800
Disclosure Date: September 21, 2021 (last updated February 23, 2025)
IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2021-29831
Disclosure Date: September 20, 2021 (last updated February 23, 2025)
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 204775.
0
Attacker Value
Unknown
CVE-2021-29809
Disclosure Date: September 19, 2021 (last updated February 23, 2025)
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204270.
0
Attacker Value
Unknown
CVE-2021-29817
Disclosure Date: September 19, 2021 (last updated February 23, 2025)
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204343.
0