|
199611
|
9.8 |
CRITICAL
Network
|
dell
|
emc_powerscale_onefs
|
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired acco…
|
CWE-287
Improper Authentication
|
CVE-2021-21502
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199612
|
9.1 |
CRITICAL
Network
|
sap
|
scimono
|
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
|
CWE-74
Injection
|
CVE-2021-21479
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199613
|
6.1 |
MEDIUM
Network
|
sap
|
web_dynpro_abap
|
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
|
CWE-601
Open Redirect
|
CVE-2021-21478
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199614
|
9.9 |
CRITICAL
Network
|
sap
|
commerce
|
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject mali…
|
CWE-94
Code Injection
|
CVE-2021-21477
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199615
|
6.1 |
MEDIUM
Network
|
sap
|
ui5
|
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerab…
|
CWE-601
Open Redirect
|
CVE-2021-21476
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199616
|
7.5 |
HIGH
Network
|
sap
|
netweaver_master_data_management_server
|
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus charac…
|
CWE-22
Path Traversal
|
CVE-2021-21475
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199617
|
6.5 |
MEDIUM
Network
|
sap
|
hana_database
|
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tam…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-21474
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199618
|
8.8 |
HIGH
Network
|
sap
|
software_provisioning_manager
|
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perfo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-21472
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199619
|
6.1 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence
|
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This coul…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-21444
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199620
|
4.3 |
MEDIUM
Network
|
otrs
|
cis_in_customer_frontend
|
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-21436
|
2024-11-21 14:48 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|