|
200041
|
6.1 |
MEDIUM
Network
|
sap
|
ui5
|
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerab…
|
CWE-601
Open Redirect
|
CVE-2021-21476
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200042
|
7.5 |
HIGH
Network
|
sap
|
netweaver_master_data_management_server
|
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus charac…
|
CWE-22
Path Traversal
|
CVE-2021-21475
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200043
|
6.5 |
MEDIUM
Network
|
sap
|
hana_database
|
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tam…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-21474
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200044
|
8.8 |
HIGH
Network
|
sap
|
software_provisioning_manager
|
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perfo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-21472
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200045
|
6.1 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence
|
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This coul…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-21444
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200046
|
4.3 |
MEDIUM
Network
|
otrs
|
cis_in_customer_frontend
|
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-21436
|
2024-11-21 14:48 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200047
|
6.5 |
MEDIUM
Network
|
otrs
|
otrs
|
Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0…
|
CWE-200
Information Exposure
|
CVE-2021-21435
|
2024-11-21 14:48 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200048
|
4.8 |
MEDIUM
Network
|
otrs
|
survey
|
Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS A…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21434
|
2024-11-21 14:48 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200049
|
5.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2021-21615
|
2024-11-21 14:48 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200050
|
7.5 |
HIGH
Network
|
zte
|
zxr10_9904_firmware zxr10_9908_firmware zxr10_9916_firmware zxr10_9904-s_firmware zxr10_9908-s_firmware
|
Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a remote attacker can trigger the vulnerability by performing a series of operat…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-21723
|
2024-11-21 14:48 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|