|
218611
|
9.8 |
CRITICAL
Network
|
ge
|
ge_communicator
|
GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Wind…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-6548
|
2024-11-21 13:46 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218612
|
7.8 |
HIGH
Local
|
ge
|
ge_communicator
|
GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI eleme…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-6546
|
2024-11-21 13:46 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218613
|
5.6 |
MEDIUM
Network
|
ge
|
ge_communicator
|
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the executi…
|
NVD-CWE-Other
|
CVE-2019-6544
|
2024-11-21 13:46 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218614
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_webaccelerator …
|
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, the Traffic Management Microkernel (TMM) may restart when a virtual server has an HTTP/2 profile with Application Layer Protocol Negotia…
|
NVD-CWE-noinfo
|
CVE-2019-6619
|
2024-11-21 13:46 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218615
|
4.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_webaccelerator …
|
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided A…
|
NVD-CWE-noinfo
|
CVE-2019-6618
|
2024-11-21 13:46 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218616
|
6.5 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_webaccelerator …
|
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc…
|
CWE-269
Improper Privilege Management
|
CVE-2019-6617
|
2024-11-21 13:46 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218617
|
7.2 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_webaccelerator …
|
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, administrative users with TMSH access can overwrite critical system files on BIG-IP which can result in …
|
NVD-CWE-noinfo
|
CVE-2019-6616
|
2024-11-21 13:46 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218618
|
4.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_webaccelerator …
|
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, Administrator and Resource Administrator roles might exploit TMSH access to bypass Appliance Mode restri…
|
NVD-CWE-noinfo
|
CVE-2019-6615
|
2024-11-21 13:46 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218619
|
5.9 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credenti…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-6158
|
2024-11-21 13:46 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218620
|
6.5 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_webaccelerator …
|
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrites in Appliance Mode were not fully effective. An authenticated attacker with a …
|
NVD-CWE-noinfo
|
CVE-2019-6614
|
2024-11-21 13:46 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|