|
196881
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By sending a specially-crafted input, a remote attacker…
|
CWE-91
Blind XPath Injection
|
CVE-2020-4774
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196882
|
6.5 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a user to execute unwanted actions on the web applica…
|
CWE-352
Origin Validation Error
|
CVE-2020-4773
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196883
|
8.1 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive informatio…
|
CWE-611
XXE
|
CVE-2020-4772
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196884
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4699
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196885
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4661
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196886
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4660
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196887
|
5.3 |
MEDIUM
Network
|
sonicwall
|
sonicos sonicosv
|
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-5143
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196888
|
6.1 |
MEDIUM
Network
|
sonicwall
|
sonicos sonicosv
|
A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5142
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196889
|
6.5 |
MEDIUM
Network
|
sonicwall
|
sonicos sonicosv
|
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, …
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-5141
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196890
|
7.5 |
HIGH
Network
|
sonicwall
|
sonicos sonicosv
|
A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads to memory addresses …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-5140
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|