Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2020
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.
CVSS Score
4.0
EPSS Score
0.0
Published
2020-11-09
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186024.
CVSS Score
4.8
EPSS Score
0.0
Published
2020-11-09
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.
CVSS Score
9.8
EPSS Score
0.007
Published
2020-11-09
CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts to edit registry values, allowing an attacker to escalate privileges.
CVSS Score
7.8
EPSS Score
0.001
Published
2020-11-09
Microweber v1.1.18 is affected by no session expiry after log-out.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-11-09
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
CVSS Score
9.8
EPSS Score
0.004
Published
2020-11-09
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-11-09
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
CVSS Score
8.1
EPSS Score
0.003
Published
2020-11-09
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw
CVSS Score
6.8
EPSS Score
0.004
Published
2020-11-09
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-11-09


Contact Us

Shodan ® - All rights reserved