Idera kayıtları
idera üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2015-9263İstismar yok | An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13).idera · uptime infrastructure monitor · CWE-434 | Kritik9,8 | — | %13,3 | 27 Ağu 2018 |
39İzleyin | CVE-2017-11470Kavram kanıtı | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.idera · uptime infrastructure monitor · CWE-89 | Kritik9,8 | — | %1,5 | 20 Tem 2017 |
39İzleyin | CVE-2017-11471Kavram kanıtı | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.idera · uptime infrastructure monitor · CWE-89 | Kritik9,8 | — | %1,5 | 20 Tem 2017 |
31İzleyin | CVE-2017-11469Kavram kanıtı | get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.idera · uptime infrastructure monitor · CWE-22 | Yüksek7,5 | — | %4,9 | 20 Tem 2017 |
31İzleyin | CVE-2015-8268İstismar yok | The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecifieidera · uptime infrastructure monitor · CWE-200 | Yüksek7,5 | — | %3,0 | 9 Haz 2016 |
30İzleyin | CVE-2015-2895İstismar yok | Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via idera · uptime infrastructure monitor · CWE-119 | Yüksek7,3 | — | %1,9 | 31 Ara 2015 |
21İzleyin | CVE-2015-2894İstismar yok | Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a deniidera · uptime infrastructure monitor · CWE-134 | Orta5,3 | — | %1,4 | 31 Ara 2015 |
21İzleyin | CVE-2015-2896İstismar yok | The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, pidera · uptime infrastructure monitor · CWE-200 | Orta5,3 | — | %1,2 | 31 Ara 2015 |
21İzleyin | CVE-2020-19587Kavram kanıtı | Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitidera · yellowfin business intelligence · CWE-79 | Orta5,4 | — | %0,9 | 13 Eyl 2022 |
- CVE-2015-926343Planlayın
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13).
KritikCVSS 9,8İstismar yokEPSS %13idera · uptime infrastructure monitor27 Ağu 2018
- CVE-2017-1147039İzleyin
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %1idera · uptime infrastructure monitor20 Tem 2017
- CVE-2017-1147139İzleyin
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %1idera · uptime infrastructure monitor20 Tem 2017
- CVE-2017-1146931İzleyin
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %5idera · uptime infrastructure monitor20 Tem 2017
- CVE-2015-826831İzleyin
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecifie
YüksekCVSS 7,5İstismar yokEPSS %3idera · uptime infrastructure monitor9 Haz 2016
- CVE-2015-289530İzleyin
Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via
YüksekCVSS 7,3İstismar yokEPSS %2idera · uptime infrastructure monitor31 Ara 2015
- CVE-2015-289421İzleyin
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a deni
OrtaCVSS 5,3İstismar yokEPSS %1idera · uptime infrastructure monitor31 Ara 2015
- CVE-2015-289621İzleyin
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, p
OrtaCVSS 5,3İstismar yokEPSS %1idera · uptime infrastructure monitor31 Ara 2015
- CVE-2020-1958721İzleyin
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbit
OrtaCVSS 5,4Kavram kanıtıEPSS %1idera · yellowfin business intelligence13 Eyl 2022