|
208541
|
6.1 |
MEDIUM
Network
|
apache fedoraproject debian canonical opensuse netapp broadcom oracle
|
http_server fedora debian_linux ubuntu_linux leap oncommand_unified_manager_core_package brocade_fabric_operating_system sd-wan_aware instantis_enterprisetrack communicatio…
|
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL…
|
CWE-601
Open Redirect
|
CVE-2020-1927
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208542
|
6.5 |
MEDIUM
Network
|
apache
|
druid
|
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if…
|
CWE-74
Injection
|
CVE-2020-1958
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208543
|
5.3 |
MEDIUM
Adjacent
|
apache oracle netapp
|
cxf peoplesoft_enterprise_peopletools communications_diameter_signaling_router communications_session_report_manager communications_element_manager enterprise_manager_base_platform …
|
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationMa…
|
NVD-CWE-noinfo
|
CVE-2020-1954
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208544
|
5.3 |
MEDIUM
Network
|
apache fedoraproject debian canonical opensuse oracle
|
http_server fedora debian_linux ubuntu_linux leap instantis_enterprisetrack communications_element_manager enterprise_manager_ops_center communications_session_report_manager<…
|
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-1934
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208545
|
6.1 |
MEDIUM
Network
|
apache
|
sling_cms
|
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attack…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1949
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208546
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
|
CWE-79
Cross-site Scripting
|
CVE-2020-1943
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208547
|
7.8 |
HIGH
Local
|
systemd_project redhat debian
|
systemd enterprise_linux openshift_container_platform discovery migration_toolkit ceph_storage debian_linux
|
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse…
|
CWE-416
Use After Free
|
CVE-2020-1712
|
2024-11-21 14:11 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208548
|
8.1 |
HIGH
Network
|
otrs
|
otrs
|
An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, passw…
|
CWE-331
Insufficient Entropy
|
CVE-2020-1773
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208549
|
7.5 |
HIGH
Network
|
otrs opensuse debian
|
otrs leap backports_sle debian_linux
|
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue…
|
NVD-CWE-noinfo
|
CVE-2020-1772
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208550
|
5.4 |
MEDIUM
Network
|
otrs
|
otrs
|
Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter enc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1771
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|