jedox kayıtları
jedox üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-522 Insufficiently Protected Credentials1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2022-47878Kavram kanıtı | Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specifyjedox · jedox · CWE-434 | Yüksek8,8 | — | %35,7 | 2 May 2023 |
38İzleyin | CVE-2022-47875Kavram kanıtı | A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary codejedox · cloud · CWE-22 | Yüksek8,8 | — | %10,2 | 2 May 2023 |
37İzleyin | CVE-2022-47876Kavram kanıtı | The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.jedox · jedox | Yüksek8,8 | — | %7,0 | 2 May 2023 |
32İzleyin | CVE-2022-47874Kavram kanıtı | Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections vijedox · cloud · CWE-863 | Orta6,5 | — | %21,1 | 2 May 2023 |
32İzleyin | CVE-2022-47879Kavram kanıtı | A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classesjedox · jedox · CWE-94 | Yüksek7,5 | — | %6,3 | 12 May 2023 |
22İzleyin | CVE-2022-47880Kavram kanıtı | An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to mojedox · jedox · CWE-522 | Orta5,3 | — | %2,9 | 12 May 2023 |
22İzleyin | CVE-2022-47877Kavram kanıtı | A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in tjedox · jedox · CWE-79 | Orta5,4 | — | %2,6 | 2 May 2023 |
20İzleyin | CVE-2007-3581İstismar yok | The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the netjedox · palo | Orta5,0 | — | %1,6 | 5 Tem 2007 |
- CVE-2022-4787846Planlayın
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify
YüksekCVSS 8,8Kavram kanıtıEPSS %36jedox · jedox2 May 2023
- CVE-2022-4787538İzleyin
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code
YüksekCVSS 8,8Kavram kanıtıEPSS %10jedox · cloud2 May 2023
- CVE-2022-4787637İzleyin
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.
YüksekCVSS 8,8Kavram kanıtıEPSS %7jedox · jedox2 May 2023
- CVE-2022-4787432İzleyin
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections vi
OrtaCVSS 6,5Kavram kanıtıEPSS %21jedox · cloud2 May 2023
- CVE-2022-4787932İzleyin
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes
YüksekCVSS 7,5Kavram kanıtıEPSS %6jedox · jedox12 May 2023
- CVE-2022-4788022İzleyin
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to mo
OrtaCVSS 5,3Kavram kanıtıEPSS %3jedox · jedox12 May 2023
- CVE-2022-4787722İzleyin
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in t
OrtaCVSS 5,4Kavram kanıtıEPSS %3jedox · jedox2 May 2023
- CVE-2007-358120İzleyin
The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the net
OrtaCVSS 5,0İstismar yokEPSS %2jedox · palo5 Tem 2007