VISAM records
16 published records for vendor visam.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-611 Improper Restriction of XML External Entity Reference8
- CWE-23 Relative Path Traversal1
- CWE-276 Incorrect Default Permissions1
- CWE-284 Improper Access Control1
- CWE-326 Inadequate Encryption Strength1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-10599No exploit | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffvisam · vbase editor · CWE-121 | Critical9.8 | — | 2.6% | Apr 3, 2020 |
35Monitor | CVE-2020-7004No exploit | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in evisam · vbase editor · CWE-276 | High8.8 | — | 0.4% | Apr 3, 2020 |
31Monitor | CVE-2020-7008No exploit | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, visam · vbase editor · CWE-23 | High7.5 | — | 1.9% | Apr 3, 2020 |
31Monitor | CVE-2020-10601No exploit | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a locavisam · vbase editor · CWE-326 | High7.8 | — | 0.3% | Apr 3, 2020 |
30Monitor | CVE-2022-3217No exploit | When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages.visam · vbase | High7.5 | — | 1.3% | Sep 16, 2022 |
30Monitor | CVE-2020-7000No exploit | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key fromvisam · vbase editor · CWE-922 | High7.5 | — | 1.1% | Apr 3, 2020 |
30Monitor | CVE-2021-38417No exploit | VISAM VBASE Editor Improper Access Controlvisam · vbase web-remote · CWE-284 | High7.5 | — | 0.8% | Jul 27, 2022 |
30Monitor | CVE-2021-42537No exploit | VISAM VBASE Editor Improper Restriction of XMLvisam · vbase web-remote · CWE-611 | High7.5 | — | 0.5% | Jul 27, 2022 |
24Monitor | CVE-2021-42535No exploit | VISAM VBASE Editor Cross Site Scriptingvisam · vbase web-remote · CWE-79 | Medium6.1 | — | 0.5% | Jul 27, 2022 |
23Monitor | CVE-2022-46300No exploit | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.visam · vbase automation base · CWE-611 | Medium5.5 | — | 4.1% | Mar 21, 2023 |
23Monitor | CVE-2022-45876No exploit | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.visam · vbase · CWE-611 | Medium5.5 | — | 3.3% | Apr 26, 2023 |
23Monitor | CVE-2022-45468No exploit | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.visam · vbase automation base · CWE-611 | Medium5.5 | — | 1.8% | Mar 21, 2023 |
23Monitor | CVE-2022-46286No exploit | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.visam · vbase automation base · CWE-611 | Medium5.5 | — | 1.8% | Mar 21, 2023 |
22Monitor | CVE-2022-43512No exploit | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.visam · vbase automation base · CWE-611 | Medium5.5 | — | 0.3% | Mar 21, 2023 |
22Monitor | CVE-2022-45121No exploit | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.visam · vbase automation base · CWE-611 | Medium5.5 | — | 0.3% | Mar 21, 2023 |
22Monitor | CVE-2022-41696No exploit | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.visam · vbase automation base · CWE-611 | Medium5.5 | — | 0.3% | Mar 21, 2023 |
- CVE-2020-1059940Plan
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buff
CriticalCVSS 9.8No exploitEPSS 3%visam · vbase editorApr 3, 2020
- CVE-2020-700435Monitor
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in e
HighCVSS 8.8No exploitEPSS 0%visam · vbase editorApr 3, 2020
- CVE-2020-700831Monitor
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use,
HighCVSS 7.5No exploitEPSS 2%visam · vbase editorApr 3, 2020
- CVE-2020-1060131Monitor
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a loca
HighCVSS 7.8No exploitEPSS 0%visam · vbase editorApr 3, 2020
- CVE-2022-321730Monitor
When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages.
HighCVSS 7.5No exploitEPSS 1%visam · vbaseSep 16, 2022
- CVE-2020-700030Monitor
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from
HighCVSS 7.5No exploitEPSS 1%visam · vbase editorApr 3, 2020
- CVE-2021-3841730Monitor
VISAM VBASE Editor Improper Access Control
HighCVSS 7.5No exploitEPSS 1%visam · vbase web-remoteJul 27, 2022
- CVE-2021-4253730Monitor
VISAM VBASE Editor Improper Restriction of XML
HighCVSS 7.5No exploitEPSS 1%visam · vbase web-remoteJul 27, 2022
- CVE-2021-4253524Monitor
VISAM VBASE Editor Cross Site Scripting
MediumCVSS 6.1No exploitEPSS 0%visam · vbase web-remoteJul 27, 2022
- CVE-2022-4630023Monitor
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
MediumCVSS 5.5No exploitEPSS 4%visam · vbase automation baseMar 21, 2023
- CVE-2022-4587623Monitor
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
MediumCVSS 5.5No exploitEPSS 3%visam · vbaseApr 26, 2023
- CVE-2022-4546823Monitor
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
MediumCVSS 5.5No exploitEPSS 2%visam · vbase automation baseMar 21, 2023
- CVE-2022-4628623Monitor
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
MediumCVSS 5.5No exploitEPSS 2%visam · vbase automation baseMar 21, 2023
- CVE-2022-4351222Monitor
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
MediumCVSS 5.5No exploitEPSS 0%visam · vbase automation baseMar 21, 2023
- CVE-2022-4512122Monitor
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
MediumCVSS 5.5No exploitEPSS 0%visam · vbase automation baseMar 21, 2023
- CVE-2022-4169622Monitor
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
MediumCVSS 5.5No exploitEPSS 0%visam · vbase automation baseMar 21, 2023