code42 kayıtları
code42 üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-426 Untrusted Search Path2
- CWE-269 Improper Privilege Management2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-502 Deserialization of Untrusted Data1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2017-9830Kavram kanıtı | Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiaticode42 · crashplan · CWE-502 | Kritik9,8 | — | %6,5 | 27 Haz 2017 |
40Planlayın | CVE-2019-15131İstismar yok | In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files tocode42 · code42 · CWE-434 | Kritik9,8 | — | %1,9 | 17 Eyl 2019 |
35İzleyin | CVE-2021-43269İstismar yok | In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config code42 · code42 · CWE-94 | Yüksek8,8 | — | %1,3 | 19 Oca 2022 |
35İzleyin | CVE-2019-11553İstismar yok | In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organizatcode42 · code42 · CWE-269 | Yüksek8,8 | — | %1,0 | 19 Tem 2019 |
31İzleyin | CVE-2018-20131İstismar yok | The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashpcode42 · code42 · CWE-732 | Yüksek7,8 | — | %0,3 | 2 Oca 2019 |
29İzleyin | CVE-2020-12736İstismar yok | Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution.code42 · code42 · CWE-74 | Yüksek7,2 | — | %2,0 | 7 Tem 2020 |
29İzleyin | CVE-2019-16861İstismar yok | Code42 server through 7.0.2 for Windows has an Untrusted Search Path.code42 · code42 · CWE-426 | Yüksek7,3 | — | %0,4 | 19 Kas 2019 |
29İzleyin | CVE-2019-16860İstismar yok | Code42 app through version 7.0.2 for Windows has an Untrusted Search Path.code42 · code42 · CWE-426 | Yüksek7,3 | — | %0,4 | 19 Kas 2019 |
28İzleyin | CVE-2019-11552İstismar yok | Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injeccode42 · code42 for enterprise · CWE-94 | Yüksek7,0 | — | %0,5 | 19 Tem 2019 |
22İzleyin | CVE-2019-11551İstismar yok | In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a filcode42 · code42 for enterprise · CWE-269 | Orta5,5 | — | %0,3 | 21 Ağu 2019 |
- CVE-2017-983041Planlayın
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiati
KritikCVSS 9,8Kavram kanıtıEPSS %6code42 · crashplan27 Haz 2017
- CVE-2019-1513140Planlayın
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to
KritikCVSS 9,8İstismar yokEPSS %2code42 · code4217 Eyl 2019
- CVE-2021-4326935İzleyin
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config
YüksekCVSS 8,8İstismar yokEPSS %1code42 · code4219 Oca 2022
- CVE-2019-1155335İzleyin
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organizat
YüksekCVSS 8,8İstismar yokEPSS %1code42 · code4219 Tem 2019
- CVE-2018-2013131İzleyin
The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashp
YüksekCVSS 7,8İstismar yokEPSS %0code42 · code422 Oca 2019
- CVE-2020-1273629İzleyin
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution.
YüksekCVSS 7,2İstismar yokEPSS %2code42 · code427 Tem 2020
- CVE-2019-1686129İzleyin
Code42 server through 7.0.2 for Windows has an Untrusted Search Path.
YüksekCVSS 7,3İstismar yokEPSS %0code42 · code4219 Kas 2019
- CVE-2019-1686029İzleyin
Code42 app through version 7.0.2 for Windows has an Untrusted Search Path.
YüksekCVSS 7,3İstismar yokEPSS %0code42 · code4219 Kas 2019
- CVE-2019-1155228İzleyin
Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injec
YüksekCVSS 7,0İstismar yokEPSS %1code42 · code42 for enterprise19 Tem 2019
- CVE-2019-1155122İzleyin
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a fil
OrtaCVSS 5,5İstismar yokEPSS %0code42 · code42 for enterprise21 Ağu 2019