CWE-650 · 12 records
Trusting HTTP Permission Methods on the Server Side
CVEs in this class
12 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-28787No exploit | IBM Security Verify Access information disclosureibm · application gateway · CWE-650 | Critical10.0 | — | 0.8% | Apr 4, 2024 |
32Monitor | CVE-2024-45098No exploit | IBM Aspera Faspex bypass securityibm · aspera faspex · CWE-650 | High8.1 | — | 0.4% | Sep 5, 2024 |
30Monitor | CVE-2024-56339No exploit | IBM WebSphere Application Server information disclosureibm · websphere application server · CWE-650 | High7.5 | — | 0.4% | Aug 7, 2025 |
28Monitor | CVE-2024-45097No exploit | IBM Aspera Faspex bypass securityibm · aspera faspex · CWE-650 | High7.1 | — | 0.3% | Sep 5, 2024 |
26Monitor | CVE-2025-21120No exploit | Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in dell · avamar · CWE-650 | Medium6.5 | — | 0.3% | Aug 4, 2025 |
23Monitor | CVE-2026-16435No exploit | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesibm · websphere application server · CWE-650 | Medium5.9 | — | 0.3% | Sep 14, 2026 |
21Monitor | CVE-2022-38115No exploit | Insecure Methods Vulnerabilitysolarwinds · security event manager · CWE-650 | Medium5.3 | — | 0.7% | Nov 23, 2022 |
21Monitor | CVE-2023-50327No exploit | IBM PowerSC weak securityibm · powersc · CWE-650 | Medium5.3 | — | 0.5% | Feb 1, 2024 |
21Monitor | CVE-2024-45282No exploit | HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)sap · s\/4 hana · CWE-650 | Medium5.3 | — | 0.3% | Oct 8, 2024 |
17Monitor | CVE-2026-42543No exploit | IRIS has a Cross-Site Request Forgery (CSRF) issuedfir-iris · iris-web · CWE-650 | Medium4.3 | — | 0.3% | Jun 4, 2026 |
17Monitor | CVE-2026-11537No exploit | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesibm · websphere application server · CWE-650 | Medium4.3 | — | 0.2% | Sep 18, 2026 |
8Monitor | CVE-2026-15753No exploit | zhinianboke xianyu-auto-reply review approve trusting http permission methods on the server sidezhinianboke · xianyu-auto-reply · CWE-650 | Low2.1 | — | 0.4% | Jul 14, 2026 |
- CVE-2024-2878740Plan
IBM Security Verify Access information disclosure
CriticalCVSS 10.0No exploitEPSS 1%ibm · application gatewayApr 4, 2024
- CVE-2024-4509832Monitor
IBM Aspera Faspex bypass security
HighCVSS 8.1No exploitEPSS 0%ibm · aspera faspexSep 5, 2024
- CVE-2024-5633930Monitor
IBM WebSphere Application Server information disclosure
HighCVSS 7.5No exploitEPSS 0%ibm · websphere application serverAug 7, 2025
- CVE-2024-4509728Monitor
IBM Aspera Faspex bypass security
HighCVSS 7.1No exploitEPSS 0%ibm · aspera faspexSep 5, 2024
- CVE-2025-2112026Monitor
Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in
MediumCVSS 6.5No exploitEPSS 0%dell · avamarAug 4, 2025
- CVE-2026-1643523Monitor
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
MediumCVSS 5.9No exploitEPSS 0%ibm · websphere application serverSep 14, 2026
- CVE-2022-3811521Monitor
Insecure Methods Vulnerability
MediumCVSS 5.3No exploitEPSS 1%solarwinds · security event managerNov 23, 2022
- CVE-2023-5032721Monitor
IBM PowerSC weak security
MediumCVSS 5.3No exploitEPSS 0%ibm · powerscFeb 1, 2024
- CVE-2024-4528221Monitor
HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)
MediumCVSS 5.3No exploitEPSS 0%sap · s\/4 hanaOct 8, 2024
- CVE-2026-4254317Monitor
IRIS has a Cross-Site Request Forgery (CSRF) issue
MediumCVSS 4.3No exploitEPSS 0%dfir-iris · iris-webJun 4, 2026
- CVE-2026-1153717Monitor
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
MediumCVSS 4.3No exploitEPSS 0%ibm · websphere application serverSep 18, 2026
- CVE-2026-157538Monitor
zhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side
LowCVSS 2.1No exploitEPSS 0%zhinianboke · xianyu-auto-replyJul 14, 2026