openiam records
5 published records for vendor openiam.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-13420No exploit | OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.openiam · openiam | Critical9.8 | — | 2.0% | Apr 6, 2021 |
39Monitor | CVE-2020-13421No exploit | OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.openiam · openiam | Critical9.8 | — | 1.1% | Apr 6, 2021 |
32Monitor | CVE-2020-13422No exploit | OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.openiam · openiam · CWE-862 | High8.1 | — | 0.9% | Apr 6, 2021 |
24Monitor | CVE-2020-13418No exploit | OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.openiam · openiam · CWE-79 | Medium6.1 | — | 0.6% | Apr 6, 2021 |
21Monitor | CVE-2020-13419No exploit | OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.openiam · openiam · CWE-22 | Medium5.3 | — | 1.2% | Apr 6, 2021 |
- CVE-2020-1342040Plan
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
CriticalCVSS 9.8No exploitEPSS 2%openiam · openiamApr 6, 2021
- CVE-2020-1342139Monitor
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
CriticalCVSS 9.8No exploitEPSS 1%openiam · openiamApr 6, 2021
- CVE-2020-1342232Monitor
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
HighCVSS 8.1No exploitEPSS 1%openiam · openiamApr 6, 2021
- CVE-2020-1341824Monitor
OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.
MediumCVSS 6.1No exploitEPSS 1%openiam · openiamApr 6, 2021
- CVE-2020-1341921Monitor
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
MediumCVSS 5.3No exploitEPSS 1%openiam · openiamApr 6, 2021