usu kayıtları
usu üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-306 Missing Authentication for Critical Function1
- CWE-502 Deserialization of Untrusted Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2022-29936İstismar yok | USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-uplusu · oracle optimization · CWE-502 | Yüksek8,8 | — | %2,2 | 29 Nis 2022 |
35İzleyin | CVE-2022-29937İstismar yok | USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commandsusu · oracle optimization · CWE-78 | Yüksek8,8 | — | %1,5 | 29 Nis 2022 |
31İzleyin | CVE-2022-29934İstismar yok | USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec.usu · oracle optimization · CWE-306 | Yüksek7,8 | — | %0,3 | 29 Nis 2022 |
30İzleyin | CVE-2022-29935İstismar yok | USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer download.usu · oracle optimization | Yüksek7,5 | — | %1,1 | 29 Nis 2022 |
- CVE-2022-2993636İzleyin
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upl
YüksekCVSS 8,8İstismar yokEPSS %2usu · oracle optimization29 Nis 2022
- CVE-2022-2993735İzleyin
USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands
YüksekCVSS 8,8İstismar yokEPSS %2usu · oracle optimization29 Nis 2022
- CVE-2022-2993431İzleyin
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec.
YüksekCVSS 7,8İstismar yokEPSS %0usu · oracle optimization29 Nis 2022
- CVE-2022-2993530İzleyin
USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer download.
YüksekCVSS 7,5İstismar yokEPSS %1usu · oracle optimization29 Nis 2022