|
196631
|
8.8 |
HIGH
Network
|
dell
|
emc_isilon_onefs emc_powerscale_onefs
|
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacke…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-5353
|
2024-11-21 14:33 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196632
|
6.1 |
MEDIUM
Network
|
dell
|
emc_avamar_server
|
Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the vi…
|
CWE-601
Open Redirect
|
CVE-2020-5329
|
2024-11-21 14:33 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196633
|
7.5 |
HIGH
Network
|
dell
|
emc_data_protection_advisor
|
Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious us…
|
NVD-CWE-Other
|
CVE-2020-5351
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196634
|
9.8 |
CRITICAL
Network
|
dell
|
emc_integrated_data_protection_appliance_firmware emc_avamar_server
|
Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3,…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-5341
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196635
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_doors_next_generation rational_quality_manager rational_team_concert engineering_workflow_ma…
|
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5004
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196636
|
6.3 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_doors_next_generation rational_quality_manager rational_team_concert engineering_workflow_ma…
|
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to netwo…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-4974
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196637
|
6.5 |
MEDIUM
Local
|
ibm
|
i2_ibase
|
IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. By using a specially-crafted .DLL file, an attacke…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-4623
|
2024-11-21 14:33 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196638
|
7.8 |
HIGH
Local
|
dell
|
supportassist_for_home_pcs supportassist_for_business_pcs
|
Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5316
|
2024-11-21 14:33 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196639
|
8.1 |
HIGH
Network
|
dell
|
emc_openmanage_enterprise-modular emc_openmanage_enterprise
|
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection vulnerability. A remote authenticated malicious use…
|
CWE-74
Injection
|
CVE-2020-5323
|
2024-11-21 14:33 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196640
|
9.1 |
CRITICAL
Network
|
dell
|
emc_openmanage_enterprise-modular
|
Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploi…
|
CWE-78
OS Command
|
CVE-2020-5322
|
2024-11-21 14:33 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|