Перейти к содержимому
Noroxi

Записи Imperva

17 опубликованных записей вендора imperva.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 5,9 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

17 записей
  • CVE-2018-16660
    40В плане

    A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated acces

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 17 %

    imperva · securesphere25 апр. 2019 г.

  • CVE-2021-45468
    40В плане

    Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WA

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    imperva · web application firewall14 янв. 2022 г.

  • CVE-2018-19646
    40В плане

    The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    imperva · securesphere28 нояб. 2018 г.

  • CVE-2011-5266
    39Наблюдать

    Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    imperva · securesphere web application firewall8 янв. 2020 г.

  • CVE-2023-50969
    39Наблюдать

    Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    28 мар. 2024 г.

  • CVE-2018-5413
    35Наблюдать

    Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privil

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    imperva · securesphere10 янв. 2019 г.

  • CVE-2018-5403
    33Наблюдать

    Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    imperva · securesphere10 янв. 2019 г.

  • CVE-2013-4091
    32Наблюдать

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    imperva · securesphere28 июн. 2013 г.

  • CVE-2010-1329
    31Наблюдать

    Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusion

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    imperva · securesphere web application firewall15 апр. 2010 г.

  • CVE-2018-5412
    31Наблюдать

    Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    imperva · securesphere10 янв. 2019 г.

  • CVE-2013-4095
    28Наблюдать

    plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authentic

    СредняяCVSS 6,5Proof of conceptEPSS 6 %

    imperva · securesphere28 июн. 2013 г.

  • CVE-2013-4094
    28Наблюдать

    The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote auth

    СредняяCVSS 6,5Proof of conceptEPSS 6 %

    imperva · securesphere28 июн. 2013 г.

  • CVE-2013-4093
    22Наблюдать

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive info

    СредняяCVSS 5,0Proof of conceptEPSS 7 %

    imperva · securesphere28 июн. 2013 г.

  • CVE-2013-4092
    21Наблюдать

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sen

    СредняяCVSS 5,0Proof of conceptEPSS 5 %

    imperva · securesphere28 июн. 2013 г.

  • CVE-2008-1463
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to i

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    imperva · securesphere24 мар. 2008 г.

  • CVE-2011-4887
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere W

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    imperva · securesphere web application firewall11 сент. 2014 г.

  • CVE-2011-0767
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    imperva · securesphere web application firewall6 июн. 2011 г.