Idera records
9 published records for vendor idera.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2015-9263No exploit | An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13).idera · uptime infrastructure monitor · CWE-434 | Critical9.8 | — | 13.3% | Aug 27, 2018 |
39Monitor | CVE-2017-11470Proof of concept | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.idera · uptime infrastructure monitor · CWE-89 | Critical9.8 | — | 1.5% | Jul 20, 2017 |
39Monitor | CVE-2017-11471Proof of concept | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.idera · uptime infrastructure monitor · CWE-89 | Critical9.8 | — | 1.5% | Jul 20, 2017 |
31Monitor | CVE-2017-11469Proof of concept | get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.idera · uptime infrastructure monitor · CWE-22 | High7.5 | — | 4.9% | Jul 20, 2017 |
31Monitor | CVE-2015-8268No exploit | The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecifieidera · uptime infrastructure monitor · CWE-200 | High7.5 | — | 3.0% | Jun 9, 2016 |
30Monitor | CVE-2015-2895No exploit | Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via idera · uptime infrastructure monitor · CWE-119 | High7.3 | — | 1.9% | Dec 31, 2015 |
21Monitor | CVE-2015-2894No exploit | Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a deniidera · uptime infrastructure monitor · CWE-134 | Medium5.3 | — | 1.4% | Dec 31, 2015 |
21Monitor | CVE-2015-2896No exploit | The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, pidera · uptime infrastructure monitor · CWE-200 | Medium5.3 | — | 1.2% | Dec 31, 2015 |
21Monitor | CVE-2020-19587Proof of concept | Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitidera · yellowfin business intelligence · CWE-79 | Medium5.4 | — | 0.9% | Sep 13, 2022 |
- CVE-2015-926343Plan
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13).
CriticalCVSS 9.8No exploitEPSS 13%idera · uptime infrastructure monitorAug 27, 2018
- CVE-2017-1147039Monitor
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
CriticalCVSS 9.8Proof of conceptEPSS 1%idera · uptime infrastructure monitorJul 20, 2017
- CVE-2017-1147139Monitor
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
CriticalCVSS 9.8Proof of conceptEPSS 1%idera · uptime infrastructure monitorJul 20, 2017
- CVE-2017-1146931Monitor
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
HighCVSS 7.5Proof of conceptEPSS 5%idera · uptime infrastructure monitorJul 20, 2017
- CVE-2015-826831Monitor
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecifie
HighCVSS 7.5No exploitEPSS 3%idera · uptime infrastructure monitorJun 9, 2016
- CVE-2015-289530Monitor
Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via
HighCVSS 7.3No exploitEPSS 2%idera · uptime infrastructure monitorDec 31, 2015
- CVE-2015-289421Monitor
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a deni
MediumCVSS 5.3No exploitEPSS 1%idera · uptime infrastructure monitorDec 31, 2015
- CVE-2015-289621Monitor
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, p
MediumCVSS 5.3No exploitEPSS 1%idera · uptime infrastructure monitorDec 31, 2015
- CVE-2020-1958721Monitor
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbit
MediumCVSS 5.4Proof of conceptEPSS 1%idera · yellowfin business intelligenceSep 13, 2022