intersystems records
10 published records for vendor intersystems.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2003-1333No exploit | Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers intersystems · cache database | Critical10.0 | — | 1.9% | Dec 31, 2003 |
28Monitor | CVE-2003-0497Proof of concept | Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying caintersystems · cache database · CWE-264 | High7.2 | — | 0.8% | Aug 7, 2003 |
28Monitor | CVE-2003-0498No exploit | Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by addintersystems · cache database · CWE-94 | High7.2 | — | 0.5% | Aug 7, 2003 |
25Monitor | CVE-2018-17152No exploit | Intersystems Cache 2017.2.2.865.0 allows XXE.intersystems · cache · CWE-611 | Medium6.4 | — | 0.7% | Jul 11, 2019 |
24Monitor | CVE-2018-17150No exploit | Intersystems Cache 2017.2.2.865.0 allows XSS.intersystems · cache · CWE-79 | Medium6.1 | — | 0.9% | Jul 11, 2019 |
21Monitor | CVE-2018-17151No exploit | Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.intersystems · cache · CWE-284 | Medium5.4 | — | 0.7% | Jul 11, 2019 |
14Monitor | CVE-2007-4427No exploit | Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0intersystems · cache database | Low3.5 | — | 0.9% | Aug 20, 2007 |
14Monitor | CVE-2007-0437No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attacintersystems · cache database | Low3.5 | — | 0.8% | Aug 20, 2007 |
8Monitor | CVE-2004-2684No exploit | Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, includinintersystems · cache database | Low2.1 | — | 0.3% | Dec 31, 2004 |
8Monitor | CVE-2004-2683No exploit | Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a seintersystems · cache | Low2.1 | — | 0.3% | Dec 31, 2004 |
- CVE-2003-133341Plan
Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers
CriticalCVSS 10.0No exploitEPSS 2%intersystems · cache databaseDec 31, 2003
- CVE-2003-049728Monitor
Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying ca
HighCVSS 7.2Proof of conceptEPSS 1%intersystems · cache databaseAug 7, 2003
- CVE-2003-049828Monitor
Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by add
HighCVSS 7.2No exploitEPSS 0%intersystems · cache databaseAug 7, 2003
- CVE-2018-1715225Monitor
Intersystems Cache 2017.2.2.865.0 allows XXE.
MediumCVSS 6.4No exploitEPSS 1%intersystems · cacheJul 11, 2019
- CVE-2018-1715024Monitor
Intersystems Cache 2017.2.2.865.0 allows XSS.
MediumCVSS 6.1No exploitEPSS 1%intersystems · cacheJul 11, 2019
- CVE-2018-1715121Monitor
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
MediumCVSS 5.4No exploitEPSS 1%intersystems · cacheJul 11, 2019
- CVE-2007-442714Monitor
Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0
LowCVSS 3.5No exploitEPSS 1%intersystems · cache databaseAug 20, 2007
- CVE-2007-043714Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attac
LowCVSS 3.5No exploitEPSS 1%intersystems · cache databaseAug 20, 2007
- CVE-2004-26848Monitor
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, includin
LowCVSS 2.1No exploitEPSS 0%intersystems · cache databaseDec 31, 2004
- CVE-2004-26838Monitor
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a se
LowCVSS 2.1No exploitEPSS 0%intersystems · cacheDec 31, 2004