Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-4129

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.
0
Attacker Value
Unknown

CVE-2023-3937

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser
Attacker Value
Unknown

CVE-2023-3864

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
Attacker Value
Unknown

CVE-2023-2679

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.
Attacker Value
Unknown

CVE-2022-0883

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.