Vulnerabilities
Vulnerable Software
Knowage-Suite:  >> Knowage  Security Vulnerabilities
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
CVSS Score
5.3
EPSS Score
0.005
Published
2019-09-05
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
CVSS Score
4.9
EPSS Score
0.011
Published
2019-09-05
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-06-13
Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analyticalDrivers/ POST request.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-06-13


Contact Us

Shodan ® - All rights reserved