|
208411
|
9.8 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attackers to execute arbit…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-25260
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208412
|
9.8 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses XML deserialization libraries in an…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-25259
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208413
|
9.8 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses ASP.NET BinaryFormatter.Deserialize…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-25258
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208414
|
9.8 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access…
|
CWE-611
XXE
|
CVE-2020-25257
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208415
|
9.1 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-25256
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208416
|
7.5 |
HIGH
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attackers to cause a denia…
|
NVD-CWE-noinfo
|
CVE-2020-25255
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208417
|
9.8 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by…
|
CWE-89
SQL Injection
|
CVE-2020-25254
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208418
|
9.8 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by…
|
CWE-89
SQL Injection
|
CVE-2020-25253
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208419
|
8.8 |
HIGH
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, …
|
CWE-352
Origin Validation Error
|
CVE-2020-25252
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208420
|
9.1 |
CRITICAL
Network
|
hyland
|
onbase
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client-side authentication is used for crit…
|
CWE-287
Improper Authentication
|
CVE-2020-25251
|
2024-11-21 14:17 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|