Записи Imperva
17 опубликованных записей вендора imperva.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 5,9 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation2
- CWE-255 Credentials Management Errors2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-16660Готовый эксплойт | A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated accesimperva · securesphere · CWE-78 | Высокая8,8 | — | 17,4 % | 25 апр. 2019 г. |
40В плане | CVE-2021-45468Proof of concept | Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAimperva · web application firewall · CWE-444 | Критическая9,8 | — | 4,0 % | 14 янв. 2022 г. |
40В плане | CVE-2018-19646Эксплойта нет | The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands imperva · securesphere · CWE-78 | Критическая9,8 | — | 3,5 % | 28 нояб. 2018 г. |
39Наблюдать | CVE-2011-5266Эксплойта нет | Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.imperva · securesphere web application firewall · CWE-89 | Критическая9,8 | — | 1,2 % | 8 янв. 2020 г. |
39Наблюдать | CVE-2023-50969Эксплойта нет | Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability | Критическая9,8 | — | 0,9 % | 28 мар. 2024 г. |
35Наблюдать | CVE-2018-5413Эксплойта нет | Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilimperva · securesphere · CWE-250 | Высокая8,8 | — | 1,3 % | 10 янв. 2019 г. |
33Наблюдать | CVE-2018-5403Эксплойта нет | Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basicimperva · securesphere · CWE-77 | Высокая8,1 | — | 2,4 % | 10 янв. 2019 г. |
32Наблюдать | CVE-2013-4091Proof of concept | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for imperva · securesphere · CWE-255 | Высокая7,5 | — | 5,6 % | 28 июн. 2013 г. |
31Наблюдать | CVE-2010-1329Эксплойта нет | Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusionimperva · securesphere web application firewall | Высокая7,8 | — | 1,4 % | 15 апр. 2010 г. |
31Наблюдать | CVE-2018-5412Эксплойта нет | Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.imperva · securesphere · CWE-77 | Высокая7,8 | — | 0,6 % | 10 янв. 2019 г. |
28Наблюдать | CVE-2013-4095Proof of concept | plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticimperva · securesphere · CWE-20 | Средняя6,5 | — | 5,9 % | 28 июн. 2013 г. |
28Наблюдать | CVE-2013-4094Proof of concept | The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authimperva · securesphere · CWE-20 | Средняя6,5 | — | 5,6 % | 28 июн. 2013 г. |
22Наблюдать | CVE-2013-4093Proof of concept | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive infoimperva · securesphere · CWE-22 | Средняя5,0 | — | 6,9 % | 28 июн. 2013 г. |
21Наблюдать | CVE-2013-4092Proof of concept | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain senimperva · securesphere · CWE-255 | Средняя5,0 | — | 4,9 % | 28 июн. 2013 г. |
17Наблюдать | CVE-2008-1463Proof of concept | Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to iimperva · securesphere · CWE-79 | Средняя4,3 | — | 1,6 % | 24 мар. 2008 г. |
17Наблюдать | CVE-2011-4887Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Wimperva · securesphere web application firewall · CWE-79 | Средняя4,3 | — | 1,3 % | 11 сент. 2014 г. |
17Наблюдать | CVE-2011-0767Эксплойта нет | Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall imperva · securesphere web application firewall · CWE-79 | Средняя4,3 | — | 1,2 % | 6 июн. 2011 г. |
- CVE-2018-1666040В плане
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated acces
ВысокаяCVSS 8,8Готовый эксплойтEPSS 17 %imperva · securesphere25 апр. 2019 г.
- CVE-2021-4546840В плане
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WA
КритическаяCVSS 9,8Proof of conceptEPSS 4 %imperva · web application firewall14 янв. 2022 г.
- CVE-2018-1964640В плане
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %imperva · securesphere28 нояб. 2018 г.
- CVE-2011-526639Наблюдать
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %imperva · securesphere web application firewall8 янв. 2020 г.
- CVE-2023-5096939Наблюдать
Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %28 мар. 2024 г.
- CVE-2018-541335Наблюдать
Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privil
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %imperva · securesphere10 янв. 2019 г.
- CVE-2018-540333Наблюдать
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %imperva · securesphere10 янв. 2019 г.
- CVE-2013-409132Наблюдать
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %imperva · securesphere28 июн. 2013 г.
- CVE-2010-132931Наблюдать
Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusion
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %imperva · securesphere web application firewall15 апр. 2010 г.
- CVE-2018-541231Наблюдать
Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %imperva · securesphere10 янв. 2019 г.
- CVE-2013-409528Наблюдать
plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authentic
СредняяCVSS 6,5Proof of conceptEPSS 6 %imperva · securesphere28 июн. 2013 г.
- CVE-2013-409428Наблюдать
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote auth
СредняяCVSS 6,5Proof of conceptEPSS 6 %imperva · securesphere28 июн. 2013 г.
- CVE-2013-409322Наблюдать
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive info
СредняяCVSS 5,0Proof of conceptEPSS 7 %imperva · securesphere28 июн. 2013 г.
- CVE-2013-409221Наблюдать
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sen
СредняяCVSS 5,0Proof of conceptEPSS 5 %imperva · securesphere28 июн. 2013 г.
- CVE-2008-146317Наблюдать
Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to i
СредняяCVSS 4,3Proof of conceptEPSS 2 %imperva · securesphere24 мар. 2008 г.
- CVE-2011-488717Наблюдать
Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere W
СредняяCVSS 4,3Эксплойта нетEPSS 1 %imperva · securesphere web application firewall11 сент. 2014 г.
- CVE-2011-076717Наблюдать
Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall
СредняяCVSS 4,3Эксплойта нетEPSS 1 %imperva · securesphere web application firewall6 июн. 2011 г.