Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2023-23951
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
0
Attacker Value
Unknown
CVE-2023-23950
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
0
Attacker Value
Unknown
CVE-2023-23949
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
0
Attacker Value
Unknown
CVE-2022-25628
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
0
Attacker Value
Unknown
CVE-2022-25627
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
0
Attacker Value
Unknown
CVE-2022-25626
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
0