Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2021-45468

Disclosure Date: January 14, 2022 (last updated February 23, 2025)
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.
Attacker Value
Unknown

CVE-2011-5266

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
Attacker Value
Unknown

CVE-2018-16660

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.
0
Attacker Value
Unknown

CVE-2018-5403

Disclosure Date: January 10, 2019 (last updated November 27, 2024)
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.
0
Attacker Value
Unknown

CVE-2018-5412

Disclosure Date: January 10, 2019 (last updated November 27, 2024)
Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.
0
Attacker Value
Unknown

CVE-2018-5413

Disclosure Date: January 10, 2019 (last updated November 27, 2024)
Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.
0
Attacker Value
Unknown

CVE-2018-19646

Disclosure Date: November 28, 2018 (last updated November 27, 2024)
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.
0
Attacker Value
Unknown

CVE-2011-4887

Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to inject arbitrary web script or HTML via the username field.
0
Attacker Value
Unknown

CVE-2013-4094

Disclosure Date: June 28, 2013 (last updated October 05, 2023)
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script.
0
Attacker Value
Unknown

CVE-2013-4093

Disclosure Date: June 28, 2013 (last updated October 05, 2023)
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information via (1) a direct request to dwr/call/plaincall/AsyncOperationsContainer.getOperationState.dwr, which reveals the installation path in the s0.filePath field, or (2) a T/keyManagement request to plain/settings.html, which reveals a temporary path in an error message.
0