Imperva kayıtları
imperva üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %5,9
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation2
- CWE-255 Credentials Management Errors2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-16660Silahlaştırılmış | A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated accesimperva · securesphere · CWE-78 | Yüksek8,8 | — | %17,4 | 25 Nis 2019 |
40Planlayın | CVE-2021-45468Kavram kanıtı | Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAimperva · web application firewall · CWE-444 | Kritik9,8 | — | %4,0 | 14 Oca 2022 |
40Planlayın | CVE-2018-19646İstismar yok | The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands imperva · securesphere · CWE-78 | Kritik9,8 | — | %3,5 | 28 Kas 2018 |
39İzleyin | CVE-2011-5266İstismar yok | Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.imperva · securesphere web application firewall · CWE-89 | Kritik9,8 | — | %1,2 | 8 Oca 2020 |
39İzleyin | CVE-2023-50969İstismar yok | Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability | Kritik9,8 | — | %0,9 | 28 Mar 2024 |
35İzleyin | CVE-2018-5413İstismar yok | Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilimperva · securesphere · CWE-250 | Yüksek8,8 | — | %1,3 | 10 Oca 2019 |
33İzleyin | CVE-2018-5403İstismar yok | Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basicimperva · securesphere · CWE-77 | Yüksek8,1 | — | %2,4 | 10 Oca 2019 |
32İzleyin | CVE-2013-4091Kavram kanıtı | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for imperva · securesphere · CWE-255 | Yüksek7,5 | — | %5,6 | 28 Haz 2013 |
31İzleyin | CVE-2010-1329İstismar yok | Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusionimperva · securesphere web application firewall | Yüksek7,8 | — | %1,4 | 15 Nis 2010 |
31İzleyin | CVE-2018-5412İstismar yok | Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.imperva · securesphere · CWE-77 | Yüksek7,8 | — | %0,6 | 10 Oca 2019 |
28İzleyin | CVE-2013-4095Kavram kanıtı | plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticimperva · securesphere · CWE-20 | Orta6,5 | — | %5,9 | 28 Haz 2013 |
28İzleyin | CVE-2013-4094Kavram kanıtı | The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authimperva · securesphere · CWE-20 | Orta6,5 | — | %5,6 | 28 Haz 2013 |
22İzleyin | CVE-2013-4093Kavram kanıtı | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive infoimperva · securesphere · CWE-22 | Orta5,0 | — | %6,9 | 28 Haz 2013 |
21İzleyin | CVE-2013-4092Kavram kanıtı | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain senimperva · securesphere · CWE-255 | Orta5,0 | — | %4,9 | 28 Haz 2013 |
17İzleyin | CVE-2008-1463Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to iimperva · securesphere · CWE-79 | Orta4,3 | — | %1,6 | 24 Mar 2008 |
17İzleyin | CVE-2011-4887İstismar yok | Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Wimperva · securesphere web application firewall · CWE-79 | Orta4,3 | — | %1,3 | 11 Eyl 2014 |
17İzleyin | CVE-2011-0767İstismar yok | Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall imperva · securesphere web application firewall · CWE-79 | Orta4,3 | — | %1,2 | 6 Haz 2011 |
- CVE-2018-1666040Planlayın
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated acces
YüksekCVSS 8,8SilahlaştırılmışEPSS %17imperva · securesphere25 Nis 2019
- CVE-2021-4546840Planlayın
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WA
KritikCVSS 9,8Kavram kanıtıEPSS %4imperva · web application firewall14 Oca 2022
- CVE-2018-1964640Planlayın
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands
KritikCVSS 9,8İstismar yokEPSS %3imperva · securesphere28 Kas 2018
- CVE-2011-526639İzleyin
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
KritikCVSS 9,8İstismar yokEPSS %1imperva · securesphere web application firewall8 Oca 2020
- CVE-2023-5096939İzleyin
Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability
KritikCVSS 9,8İstismar yokEPSS %128 Mar 2024
- CVE-2018-541335İzleyin
Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privil
YüksekCVSS 8,8İstismar yokEPSS %1imperva · securesphere10 Oca 2019
- CVE-2018-540333İzleyin
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic
YüksekCVSS 8,1İstismar yokEPSS %2imperva · securesphere10 Oca 2019
- CVE-2013-409132İzleyin
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for
YüksekCVSS 7,5Kavram kanıtıEPSS %6imperva · securesphere28 Haz 2013
- CVE-2010-132931İzleyin
Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusion
YüksekCVSS 7,8İstismar yokEPSS %1imperva · securesphere web application firewall15 Nis 2010
- CVE-2018-541231İzleyin
Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.
YüksekCVSS 7,8İstismar yokEPSS %1imperva · securesphere10 Oca 2019
- CVE-2013-409528İzleyin
plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authentic
OrtaCVSS 6,5Kavram kanıtıEPSS %6imperva · securesphere28 Haz 2013
- CVE-2013-409428İzleyin
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote auth
OrtaCVSS 6,5Kavram kanıtıEPSS %6imperva · securesphere28 Haz 2013
- CVE-2013-409322İzleyin
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive info
OrtaCVSS 5,0Kavram kanıtıEPSS %7imperva · securesphere28 Haz 2013
- CVE-2013-409221İzleyin
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sen
OrtaCVSS 5,0Kavram kanıtıEPSS %5imperva · securesphere28 Haz 2013
- CVE-2008-146317İzleyin
Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to i
OrtaCVSS 4,3Kavram kanıtıEPSS %2imperva · securesphere24 Mar 2008
- CVE-2011-488717İzleyin
Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere W
OrtaCVSS 4,3İstismar yokEPSS %1imperva · securesphere web application firewall11 Eyl 2014
- CVE-2011-076717İzleyin
Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall
OrtaCVSS 4,3İstismar yokEPSS %1imperva · securesphere web application firewall6 Haz 2011