bpcbt records
11 published records for vendor bpcbt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-269 Improper Privilege Management1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-384 Session Fixation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-38619No exploit | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroupsbpcbt · smartvista front-end · CWE-89 | Critical9.8 | — | 0.9% | Sep 20, 2022 |
35Monitor | CVE-2022-38615No exploit | SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and Userbpcbt · smartvista front-end · CWE-89 | High8.8 | — | 0.9% | Sep 9, 2022 |
35Monitor | CVE-2022-38617No exploit | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/vbpcbt · smartvista · CWE-89 | High8.8 | — | 0.9% | Sep 19, 2022 |
35Monitor | CVE-2022-38616No exploit | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.bpcbt · smartvista front-end · CWE-89 | High8.8 | — | 0.9% | Sep 13, 2022 |
35Monitor | CVE-2022-38618No exploit | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_idbpcbt · smartvista · CWE-89 | High8.8 | — | 0.8% | Sep 19, 2022 |
35Monitor | CVE-2018-15206No exploit | BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.bpcbt · smartvista · CWE-352 | High8.8 | — | 0.6% | Apr 30, 2019 |
30Monitor | CVE-2018-15208No exploit | BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.bpcbt · smartvista · CWE-384 | High7.5 | — | 1.1% | Apr 30, 2019 |
30Monitor | CVE-2022-38614No exploit | An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files vibpcbt · smartvista cardgen · CWE-22 | High7.5 | — | 1.1% | Sep 9, 2022 |
28Monitor | CVE-2018-15207No exploit | BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to abpcbt · smartvista · CWE-269 | High7.2 | — | 1.4% | Apr 30, 2019 |
26Monitor | CVE-2022-38613No exploit | A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.bpcbt · smartvista cardgen · CWE-22 | Medium6.5 | — | 1.0% | Sep 9, 2022 |
24Monitor | CVE-2022-35554No exploit | Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute jabpcbt · smartvista · CWE-79 | Medium6.1 | — | 0.5% | Aug 19, 2022 |
- CVE-2022-3861939Monitor
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups
CriticalCVSS 9.8No exploitEPSS 1%bpcbt · smartvista front-endSep 20, 2022
- CVE-2022-3861535Monitor
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and User
HighCVSS 8.8No exploitEPSS 1%bpcbt · smartvista front-endSep 9, 2022
- CVE-2022-3861735Monitor
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/v
HighCVSS 8.8No exploitEPSS 1%bpcbt · smartvistaSep 19, 2022
- CVE-2022-3861635Monitor
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.
HighCVSS 8.8No exploitEPSS 1%bpcbt · smartvista front-endSep 13, 2022
- CVE-2022-3861835Monitor
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id
HighCVSS 8.8No exploitEPSS 1%bpcbt · smartvistaSep 19, 2022
- CVE-2018-1520635Monitor
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
HighCVSS 8.8No exploitEPSS 1%bpcbt · smartvistaApr 30, 2019
- CVE-2018-1520830Monitor
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
HighCVSS 7.5No exploitEPSS 1%bpcbt · smartvistaApr 30, 2019
- CVE-2022-3861430Monitor
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files vi
HighCVSS 7.5No exploitEPSS 1%bpcbt · smartvista cardgenSep 9, 2022
- CVE-2018-1520728Monitor
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to a
HighCVSS 7.2No exploitEPSS 1%bpcbt · smartvistaApr 30, 2019
- CVE-2022-3861326Monitor
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
MediumCVSS 6.5No exploitEPSS 1%bpcbt · smartvista cardgenSep 9, 2022
- CVE-2022-3555424Monitor
Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute ja
MediumCVSS 6.1No exploitEPSS 1%bpcbt · smartvistaAug 19, 2022