|
197271
|
7.2 |
HIGH
Network
|
microfocus
|
netiq_advanced_authentication
|
Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
|
CWE-287
Improper Authentication
|
CVE-2021-22497
|
2024-11-21 14:50 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197272
|
6.5 |
MEDIUM
Network
|
microfocus
|
application_automation_tools
|
Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow acce…
|
CWE-862
Missing Authorization
|
CVE-2021-22513
|
2024-11-21 14:50 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197273
|
6.5 |
MEDIUM
Network
|
microfocus
|
application_automation_tools
|
Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability coul…
|
CWE-352
Origin Validation Error
|
CVE-2021-22512
|
2024-11-21 14:50 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197274
|
6.5 |
MEDIUM
Network
|
microfocus
|
application_automation_tools
|
Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could …
|
CWE-295
Improper Certificate Validation
|
CVE-2021-22511
|
2024-11-21 14:50 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197275
|
6.1 |
MEDIUM
Network
|
microfocus
|
application_automation_tools
|
Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects all version 6.7 and earlier versions.
|
CWE-79
Cross-site Scripting
|
CVE-2021-22510
|
2024-11-21 14:50 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197276
|
9.8 |
CRITICAL
Network
|
microfocus
|
operations_bridge_manager
|
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user auth…
|
CWE-287
Improper Authentication
|
CVE-2021-22507
|
2024-11-21 14:50 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197277
|
6.5 |
MEDIUM
Network
|
github
|
enterprise_server
|
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadat…
|
NVD-CWE-Other
|
CVE-2021-22865
|
2024-11-21 14:50 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197278
|
7.5 |
HIGH
Network
|
apache oracle
|
cxf business_intelligence communications_session_route_manager communications_session_report_manager communications_element_manager communications_diameter_intelligence_hub
|
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR))…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22696
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197279
|
3.7 |
LOW
Network
|
haxx fedoraproject netapp broadcom debian siemens oracle splunk
|
libcurl fedora solidfire hci_management_node hci_storage_node fabric_operating_system debian_linux sinec_infrastructure_network_services communications_billing_and_revenue_man…
|
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-22890
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197280
|
5.3 |
MEDIUM
Network
|
haxx fedoraproject netapp broadcom debian siemens oracle splunk
|
libcurl fedora solidfire hci_management_node hci_storage_node hci_compute_node fabric_operating_system debian_linux sinec_infrastructure_network_services communications_bil…
|
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip o…
|
CWE-200
Information Exposure
|
CVE-2021-22876
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|