smarsh kayıtları
smarsh üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %25
- Silahlaştırılmış
- 2 · %25
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 34 gün
Tekrar eden sınıflar
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-316 Cleartext Storage of Sensitive Information in Memory1
- CWE-328 Use of Weak Hash1
- CWE-528 Exposure of Core Dump File to an Unauthorized Control Sphere1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2025-48927Silahlaştırılmış | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploitsmarsh · telemessage · CWE-1188 | Orta5,3 | KEV | %11,1 | 28 May 2025 |
46Planlayın | CVE-2025-48928Silahlaştırılmış | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" insmarsh · telemessage · CWE-528 | Orta4,0 | KEV | %0,6 | 28 May 2025 |
39İzleyin | CVE-2025-48929İstismar yok | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiratsmarsh · telemessage · CWE-922 | Kritik9,8 | — | %0,3 | 28 May 2025 |
30İzleyin | CVE-2025-47730İstismar yok | The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Sismarsh · telemessage · CWE-798 | Yüksek7,5 | — | %0,4 | 8 May 2025 |
30İzleyin | CVE-2025-48925İstismar yok | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash assmarsh · telemessage · CWE-836 | Yüksek7,5 | — | %0,3 | 28 May 2025 |
30İzleyin | CVE-2025-48926İstismar yok | The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telepsmarsh · telemessage · CWE-288 | Yüksek7,5 | — | %0,3 | 28 May 2025 |
22İzleyin | CVE-2025-48931İstismar yok | The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbosmarsh · telemessage · CWE-328 | Orta5,5 | — | %0,1 | 28 May 2025 |
21İzleyin | CVE-2025-48930İstismar yok | The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to asmarsh · telemessage · CWE-316 | Orta5,3 | — | %0,1 | 28 May 2025 |
- CVE-2025-4892754Planlayın
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %11smarsh · telemessage28 May 2025
- CVE-2025-4892846Planlayın
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in
OrtaCVSS 4,0KEVSilahlaştırılmışEPSS %1smarsh · telemessage28 May 2025
- CVE-2025-4892939İzleyin
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat
KritikCVSS 9,8İstismar yokEPSS %0smarsh · telemessage28 May 2025
- CVE-2025-4773030İzleyin
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Si
YüksekCVSS 7,5İstismar yokEPSS %0smarsh · telemessage8 May 2025
- CVE-2025-4892530İzleyin
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as
YüksekCVSS 7,5İstismar yokEPSS %0smarsh · telemessage28 May 2025
- CVE-2025-4892630İzleyin
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telep
YüksekCVSS 7,5İstismar yokEPSS %0smarsh · telemessage28 May 2025
- CVE-2025-4893122İzleyin
The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbo
OrtaCVSS 5,5İstismar yokEPSS %0smarsh · telemessage28 May 2025
- CVE-2025-4893021İzleyin
The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to a
OrtaCVSS 5,3İstismar yokEPSS %0smarsh · telemessage28 May 2025