Show filters
156 Total Results
Displaying 1-10 of 156
Sort by:
Attacker Value
High
CVE-2022-22965
Disclosure Date: April 01, 2022 (last updated October 07, 2023)
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
7
Attacker Value
Unknown
CVE-2024-53915
Disclosure Date: November 24, 2024 (last updated December 21, 2024)
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
0
Attacker Value
Unknown
CVE-2024-53914
Disclosure Date: November 24, 2024 (last updated December 21, 2024)
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
0
Attacker Value
Unknown
CVE-2024-53913
Disclosure Date: November 24, 2024 (last updated December 21, 2024)
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
0
Attacker Value
Unknown
CVE-2024-53912
Disclosure Date: November 24, 2024 (last updated December 21, 2024)
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
0
Attacker Value
Unknown
CVE-2024-53911
Disclosure Date: November 24, 2024 (last updated December 21, 2024)
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
0
Attacker Value
Unknown
CVE-2024-53910
Disclosure Date: November 24, 2024 (last updated December 21, 2024)
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
0
Attacker Value
Unknown
CVE-2024-53909
Disclosure Date: November 24, 2024 (last updated December 21, 2024)
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
0
Attacker Value
Unknown
CVE-2024-47854
Disclosure Date: October 04, 2024 (last updated November 14, 2024)
An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.
0
Attacker Value
Unknown
CVE-2024-28222
Disclosure Date: March 07, 2024 (last updated January 22, 2025)
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
0