Записи Idera
9 опубликованных записей вендора idera.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2015-9263Эксплойта нет | An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13).idera · uptime infrastructure monitor · CWE-434 | Критическая9,8 | — | 13,3 % | 27 авг. 2018 г. |
39Наблюдать | CVE-2017-11470Proof of concept | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.idera · uptime infrastructure monitor · CWE-89 | Критическая9,8 | — | 1,5 % | 20 июл. 2017 г. |
39Наблюдать | CVE-2017-11471Proof of concept | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.idera · uptime infrastructure monitor · CWE-89 | Критическая9,8 | — | 1,5 % | 20 июл. 2017 г. |
31Наблюдать | CVE-2017-11469Proof of concept | get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.idera · uptime infrastructure monitor · CWE-22 | Высокая7,5 | — | 4,9 % | 20 июл. 2017 г. |
31Наблюдать | CVE-2015-8268Эксплойта нет | The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecifieidera · uptime infrastructure monitor · CWE-200 | Высокая7,5 | — | 3,0 % | 9 июн. 2016 г. |
30Наблюдать | CVE-2015-2895Эксплойта нет | Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via idera · uptime infrastructure monitor · CWE-119 | Высокая7,3 | — | 1,9 % | 31 дек. 2015 г. |
21Наблюдать | CVE-2015-2894Эксплойта нет | Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a deniidera · uptime infrastructure monitor · CWE-134 | Средняя5,3 | — | 1,4 % | 31 дек. 2015 г. |
21Наблюдать | CVE-2015-2896Эксплойта нет | The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, pidera · uptime infrastructure monitor · CWE-200 | Средняя5,3 | — | 1,2 % | 31 дек. 2015 г. |
21Наблюдать | CVE-2020-19587Proof of concept | Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitidera · yellowfin business intelligence · CWE-79 | Средняя5,4 | — | 0,9 % | 13 сент. 2022 г. |
- CVE-2015-926343В плане
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13).
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %idera · uptime infrastructure monitor27 авг. 2018 г.
- CVE-2017-1147039Наблюдать
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 1 %idera · uptime infrastructure monitor20 июл. 2017 г.
- CVE-2017-1147139Наблюдать
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 1 %idera · uptime infrastructure monitor20 июл. 2017 г.
- CVE-2017-1146931Наблюдать
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %idera · uptime infrastructure monitor20 июл. 2017 г.
- CVE-2015-826831Наблюдать
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecifie
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %idera · uptime infrastructure monitor9 июн. 2016 г.
- CVE-2015-289530Наблюдать
Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via
ВысокаяCVSS 7,3Эксплойта нетEPSS 2 %idera · uptime infrastructure monitor31 дек. 2015 г.
- CVE-2015-289421Наблюдать
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a deni
СредняяCVSS 5,3Эксплойта нетEPSS 1 %idera · uptime infrastructure monitor31 дек. 2015 г.
- CVE-2015-289621Наблюдать
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, p
СредняяCVSS 5,3Эксплойта нетEPSS 1 %idera · uptime infrastructure monitor31 дек. 2015 г.
- CVE-2020-1958721Наблюдать
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbit
СредняяCVSS 5,4Proof of conceptEPSS 1 %idera · yellowfin business intelligence13 сент. 2022 г.