igniterealtime kayıtları
igniterealtime üreticisine ait 43 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2,3
- Silahlaştırılmış
- 2 · %4,7
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %37,2
- Yayından KEV’e ortanca
- 90 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-295 Improper Certificate Validation2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-287 Improper Authentication2
- CWE-345 Insufficient Verification of Data Authenticity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
43 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-32315Silahlaştırılmış | Openfire administration console authentication bypassigniterealtime · openfire · CWE-22 | Yüksek7,5 | KEV | %100,0 | 26 May 2023 |
55Planlayın | CVE-2008-6508Silahlaştırılmış | Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypigniterealtime · openfire · CWE-22 | Yüksek7,5 | — | %83,7 | 23 Mar 2009 |
49Planlayın | CVE-2019-18394Kavram kanıtı | A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to sendigniterealtime · openfire · CWE-918 | Kritik9,8 | — | %32,3 | 24 Eki 2019 |
46Planlayın | CVE-2015-6973Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authenticigniterealtime · openfire · CWE-352 | Orta6,8 | — | %64,8 | 16 Eyl 2015 |
45Planlayın | CVE-2021-45967Kavram kanıtı | An issue was discovered in Pascom Cloud Phone System before 7.20.x.pascom · cloud phone system · CWE-22 | Kritik9,8 | — | %20,8 | 18 Mar 2022 |
39İzleyin | CVE-2024-25421İstismar yok | An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.igniterealtime · openfire · CWE-250 | Kritik9,8 | — | %1,7 | 26 Mar 2024 |
36İzleyin | CVE-2020-12772İstismar yok | An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows.igniterealtime · spark · CWE-200 | Yüksek8,8 | — | %1,7 | 12 May 2020 |
32İzleyin | CVE-2014-2741İstismar yok | nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of compressed XML elements,igniterealtime · openfire · CWE-264 | Yüksek7,8 | — | %3,8 | 10 Nis 2014 |
32İzleyin | CVE-2017-2815İstismar yok | An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0.igniterealtime · user import export · CWE-611 | Yüksek8,1 | — | %0,9 | 15 May 2018 |
31İzleyin | CVE-2008-6509Kavram kanıtı | SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commigniterealtime · openfire · CWE-89 | Yüksek7,5 | — | %2,0 | 23 Mar 2009 |
31İzleyin | CVE-2014-3451İstismar yok | OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.igniterealtime · openfire · CWE-295 | Yüksek7,5 | — | %1,8 | 18 Ağu 2017 |
28İzleyin | CVE-2015-7707Kavram kanıtı | Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jigniterealtime · openfire · CWE-264 | Orta6,5 | — | %6,0 | 5 Eki 2015 |
28İzleyin | CVE-2024-25420İstismar yok | An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system properigniterealtime · openfire · CWE-273 | Yüksek7,2 | — | %1,4 | 26 Mar 2024 |
27İzleyin | CVE-2014-5075İstismar yok | The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostnredhat · jboss fuse · CWE-310 | Orta6,8 | — | %0,9 | 25 Eki 2014 |
26İzleyin | CVE-2009-1596İstismar yok | Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration settinigniterealtime · openfire · CWE-287 | Orta6,5 | — | %1,2 | 11 May 2009 |
25İzleyin | CVE-2019-18393Kavram kanıtı | PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directigniterealtime · openfire · CWE-22 | Orta5,3 | — | %13,9 | 24 Eki 2019 |
25İzleyin | CVE-2018-11688İstismar yok | Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.igniterealtime · openfire · CWE-79 | Orta6,1 | — | %2,4 | 13 Haz 2018 |
24İzleyin | CVE-2008-6511Kavram kanıtı | Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites andigniterealtime · openfire · CWE-20 | Orta5,8 | — | %1,8 | 23 Mar 2009 |
24İzleyin | CVE-2019-20363İstismar yok | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.igniterealtime · openfire · CWE-79 | Orta6,1 | — | %1,4 | 8 Oca 2020 |
24İzleyin | CVE-2019-20366İstismar yok | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.igniterealtime · openfire · CWE-79 | Orta6,1 | — | %1,3 | 8 Oca 2020 |
24İzleyin | CVE-2019-20365İstismar yok | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.igniterealtime · openfire · CWE-79 | Orta6,1 | — | %1,2 | 8 Oca 2020 |
24İzleyin | CVE-2019-20364İstismar yok | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.igniterealtime · openfire · CWE-79 | Orta6,1 | — | %1,2 | 8 Oca 2020 |
24İzleyin | CVE-2020-24604İstismar yok | A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1.igniterealtime · openfire · CWE-79 | Orta6,1 | — | %1,2 | 2 Eyl 2020 |
24İzleyin | CVE-2020-24602İstismar yok | Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URigniterealtime · openfire · CWE-79 | Orta6,1 | — | %1,0 | 2 Eyl 2020 |
24İzleyin | CVE-2020-35200İstismar yok | Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.igniterealtime · openfire · CWE-79 | Orta6,1 | — | %0,9 | 12 Ara 2020 |
- CVE-2023-3231590Hemen
Openfire administration console authentication bypass
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100igniterealtime · openfire26 May 2023
- CVE-2008-650855Planlayın
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to byp
YüksekCVSS 7,5SilahlaştırılmışEPSS %84igniterealtime · openfire23 Mar 2009
- CVE-2019-1839449Planlayın
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send
KritikCVSS 9,8Kavram kanıtıEPSS %32igniterealtime · openfire24 Eki 2019
- CVE-2015-697346Planlayın
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentic
OrtaCVSS 6,8Kavram kanıtıEPSS %65igniterealtime · openfire16 Eyl 2015
- CVE-2021-4596745Planlayın
An issue was discovered in Pascom Cloud Phone System before 7.20.x.
KritikCVSS 9,8Kavram kanıtıEPSS %21pascom · cloud phone system18 Mar 2022
- CVE-2024-2542139İzleyin
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.
KritikCVSS 9,8İstismar yokEPSS %2igniterealtime · openfire26 Mar 2024
- CVE-2020-1277236İzleyin
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows.
YüksekCVSS 8,8İstismar yokEPSS %2igniterealtime · spark12 May 2020
- CVE-2014-274132İzleyin
nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of compressed XML elements,
YüksekCVSS 7,8İstismar yokEPSS %4igniterealtime · openfire10 Nis 2014
- CVE-2017-281532İzleyin
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0.
YüksekCVSS 8,1İstismar yokEPSS %1igniterealtime · user import export15 May 2018
- CVE-2008-650931İzleyin
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL comm
YüksekCVSS 7,5Kavram kanıtıEPSS %2igniterealtime · openfire23 Mar 2009
- CVE-2014-345131İzleyin
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
YüksekCVSS 7,5İstismar yokEPSS %2igniterealtime · openfire18 Ağu 2017
- CVE-2015-770728İzleyin
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.j
OrtaCVSS 6,5Kavram kanıtıEPSS %6igniterealtime · openfire5 Eki 2015
- CVE-2024-2542028İzleyin
An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system proper
YüksekCVSS 7,2İstismar yokEPSS %1igniterealtime · openfire26 Mar 2024
- CVE-2014-507527İzleyin
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostn
OrtaCVSS 6,8İstismar yokEPSS %1redhat · jboss fuse25 Eki 2014
- CVE-2009-159626İzleyin
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration settin
OrtaCVSS 6,5İstismar yokEPSS %1igniterealtime · openfire11 May 2009
- CVE-2019-1839325İzleyin
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home direct
OrtaCVSS 5,3Kavram kanıtıEPSS %14igniterealtime · openfire24 Eki 2019
- CVE-2018-1168825İzleyin
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
OrtaCVSS 6,1İstismar yokEPSS %2igniterealtime · openfire13 Haz 2018
- CVE-2008-651124İzleyin
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and
OrtaCVSS 5,8Kavram kanıtıEPSS %2igniterealtime · openfire23 Mar 2009
- CVE-2019-2036324İzleyin
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
OrtaCVSS 6,1İstismar yokEPSS %1igniterealtime · openfire8 Oca 2020
- CVE-2019-2036624İzleyin
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
OrtaCVSS 6,1İstismar yokEPSS %1igniterealtime · openfire8 Oca 2020
- CVE-2019-2036524İzleyin
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
OrtaCVSS 6,1İstismar yokEPSS %1igniterealtime · openfire8 Oca 2020
- CVE-2019-2036424İzleyin
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
OrtaCVSS 6,1İstismar yokEPSS %1igniterealtime · openfire8 Oca 2020
- CVE-2020-2460424İzleyin
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1.
OrtaCVSS 6,1İstismar yokEPSS %1igniterealtime · openfire2 Eyl 2020
- CVE-2020-2460224İzleyin
Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious UR
OrtaCVSS 6,1İstismar yokEPSS %1igniterealtime · openfire2 Eyl 2020
- CVE-2020-3520024İzleyin
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
OrtaCVSS 6,1İstismar yokEPSS %1igniterealtime · openfire12 Ara 2020