|
210401
|
6.5 |
MEDIUM
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of other bugs. This follo…
|
NVD-CWE-noinfo
|
CVE-2020-11631
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210402
|
9.8 |
CRITICAL
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allo…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11630
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210403
|
7.2 |
HIGH
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, i…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-11629
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210404
|
5.3 |
MEDIUM
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. …
|
CWE-863
Incorrect Authorization
|
CVE-2020-11628
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210405
|
8.8 |
HIGH
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
|
CWE-352
Origin Validation Error
|
CVE-2020-11627
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210406
|
6.1 |
MEDIUM
Network
|
primekey
|
ejbca
|
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11626
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210407
|
9.8 |
CRITICAL
Network
|
opsramp
|
gateway
|
OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-11543
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210408
|
8.1 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager retail_xstore_point_of_service primavera_unifier weblogic_server retail_merchandising_…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11620
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210409
|
8.1 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager retail_xstore_point_of_service primavera_unifier weblogic_server retail_merchandising_…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11619
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210410
|
6.1 |
MEDIUM
Network
|
wpleadplus
|
wp_lead_plus_x
|
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-pos…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11509
|
2024-11-21 13:58 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|