|
197671
|
6.5 |
MEDIUM
Network
|
hcltech
|
hcl_domino
|
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access in…
|
CWE-352
Origin Validation Error
|
CVE-2020-4127
|
2024-11-21 14:32 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197672
|
6.5 |
MEDIUM
Network
|
vmware
|
sd-wan_orchestrator
|
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. A…
|
CWE-89
SQL Injection
|
CVE-2020-4003
|
2024-11-21 14:32 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197673
|
7.2 |
HIGH
Network
|
vmware
|
sd-wan_orchestrator
|
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privi…
|
NVD-CWE-noinfo
|
CVE-2020-4002
|
2024-11-21 14:32 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197674
|
9.8 |
CRITICAL
Network
|
vmware
|
sd-wan_orchestrator
|
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to t…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-4001
|
2024-11-21 14:32 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197675
|
8.8 |
HIGH
Network
|
vmware
|
sd-wan_orchestrator
|
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal. An authenticated SD-WAN Orchestrator user is ab…
|
CWE-22
Path Traversal
|
CVE-2020-4000
|
2024-11-21 14:32 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197676
|
8.8 |
HIGH
Network
|
vmware
|
sd-wan_orchestrator
|
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue. An authenticated SD-WAN Orches…
|
NVD-CWE-noinfo
|
CVE-2020-3985
|
2024-11-21 14:32 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197677
|
6.5 |
MEDIUM
Network
|
vmware
|
sd-wan_orchestrator
|
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit …
|
CWE-89
SQL Injection
|
CVE-2020-3984
|
2024-11-21 14:32 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197678
|
9.1 |
CRITICAL
Network
|
vmware
|
identity_manager identity_manager_connector one_access vrealize_suite_lifecycle_manager cloud_foundation
|
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
|
CWE-78
OS Command
|
CVE-2020-4006
|
2024-11-21 14:32 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197679
|
7.8 |
HIGH
Local
|
vmware
|
cloud_foundation esxi
|
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls…
|
NVD-CWE-noinfo
|
CVE-2020-4005
|
2024-11-21 14:32 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197680
|
8.2 |
HIGH
Local
|
vmware
|
fusion workstation cloud_foundation esxi
|
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free v…
|
CWE-416
Use After Free
|
CVE-2020-4004
|
2024-11-21 14:32 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|