Sage kayıtları
sage üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %7,1
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-798 Use of Hard-coded Credentials4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-276 Incorrect Default Permissions1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2020-7388Silahlaştırılmış | Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofingsage · adxadmin · CWE-290 | Kritik9,8 | — | %69,4 | 22 Tem 2021 |
39İzleyin | CVE-2022-34324İstismar yok | Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add sage · sage xrt business exchange · CWE-89 | Yüksek8,8 | — | %11,9 | 1 Oca 2023 |
39İzleyin | CVE-2022-41397İstismar yok | The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKesage · sage 300 · CWE-798 | Kritik9,8 | — | %0,7 | 28 Nis 2023 |
39İzleyin | CVE-2022-41400İstismar yok | Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAMsage · sage 300 · CWE-798 | Kritik9,8 | — | %0,6 | 28 Nis 2023 |
39İzleyin | CVE-2023-2809İstismar yok | Use of Cleartext credentials in Sage 200 Spainsage · sage 200 spain · CWE-312 | Kritik9,8 | — | %0,4 | 4 Eki 2023 |
36İzleyin | CVE-2017-3183İstismar yok | Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full access to prisage · xrt treasury · CWE-639 | Yüksek8,8 | — | %2,1 | 24 Tem 2018 |
36İzleyin | CVE-2022-34322İstismar yok | Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the contesage · sage enterprise intelligence · CWE-79 | Kritik9,0 | — | %0,8 | 1 Oca 2023 |
32İzleyin | CVE-2020-7387Silahlaştırılmış | Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actorsage · adxadmin · CWE-200 | Orta5,3 | — | %36,4 | 22 Tem 2021 |
32İzleyin | CVE-2024-48646İstismar yok | An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validatiosage · sage frp 1000 · CWE-434 | Yüksek8,1 | — | %0,5 | 30 Eki 2024 |
31İzleyin | CVE-2021-45492İstismar yok | In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in thesage · sage 300 · CWE-732 | Yüksek7,8 | — | %0,3 | 14 Tem 2022 |
31İzleyin | CVE-2022-38583İstismar yok | On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configurasage · sage 300 · CWE-276 | Yüksek7,8 | — | %0,3 | 28 Nis 2023 |
30İzleyin | CVE-2019-25053İstismar yok | A path traversal vulnerability exists in Sage FRP 1000 before November 2019.sage · sage frp 1000 · CWE-22 | Yüksek7,5 | — | %1,1 | 27 Oca 2023 |
30İzleyin | CVE-2022-41399İstismar yok | The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypsage · sage 300 · CWE-798 | Yüksek7,5 | — | %0,6 | 28 Nis 2023 |
30İzleyin | CVE-2022-41398İstismar yok | The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr isage · sage 300 · CWE-798 | Yüksek7,5 | — | %0,5 | 28 Nis 2023 |
29İzleyin | CVE-2020-7389İstismar yok | Sage X3 Syracuse Missing Authentication for Critical Function in Developer Environmentsage · syracuse · CWE-306 | Yüksek7,2 | — | %2,1 | 22 Tem 2021 |
28İzleyin | CVE-2006-4712İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScrisage · sage · CWE-79 | Orta6,8 | — | %2,2 | 12 Eyl 2006 |
28İzleyin | CVE-2024-48647İstismar yok | A file disclosure vulnerability exists in Sage 1000 v7.0.0.sage · sage frp 1000 · CWE-552 | Yüksek7,2 | — | %0,8 | 30 Eki 2024 |
28İzleyin | CVE-2023-31867İstismar yok | Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.sage · x3 · CWE-1236 | Yüksek7,2 | — | %0,8 | 22 Haz 2023 |
24İzleyin | CVE-2024-48648İstismar yok | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0.sage · sage frp 1000 · CWE-79 | Orta6,1 | — | %0,3 | 30 Eki 2024 |
22İzleyin | CVE-2003-1242Kavram kanıtı | Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path isage · sage | Orta5,0 | — | %6,8 | 31 Ara 2003 |
21İzleyin | CVE-2020-7390İstismar yok | Sage X3 Syracuse Persistent XSS in Edit User pagesage · syracuse · CWE-79 | Orta5,4 | — | %0,6 | 22 Tem 2021 |
21İzleyin | CVE-2020-13893İstismar yok | Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web ssage · easypay · CWE-79 | Orta5,4 | — | %0,5 | 18 Eki 2020 |
21İzleyin | CVE-2022-34323İstismar yok | Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context sage · sage xrt business exchange · CWE-79 | Orta5,4 | — | %0,4 | 1 Oca 2023 |
21İzleyin | CVE-2023-31868İstismar yok | Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS).sage · x3 · CWE-79 | Orta5,4 | — | %0,3 | 22 Haz 2023 |
18İzleyin | CVE-2003-1243Kavram kanıtı | Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parametersage · sage | Orta4,3 | — | %3,5 | 31 Ara 2003 |
- CVE-2020-738860Bu hafta
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
KritikCVSS 9,8SilahlaştırılmışEPSS %69sage · adxadmin22 Tem 2021
- CVE-2022-3432439İzleyin
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add
YüksekCVSS 8,8İstismar yokEPSS %12sage · sage xrt business exchange1 Oca 2023
- CVE-2022-4139739İzleyin
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKe
KritikCVSS 9,8İstismar yokEPSS %1sage · sage 30028 Nis 2023
- CVE-2022-4140039İzleyin
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM
KritikCVSS 9,8İstismar yokEPSS %1sage · sage 30028 Nis 2023
- CVE-2023-280939İzleyin
Use of Cleartext credentials in Sage 200 Spain
KritikCVSS 9,8İstismar yokEPSS %0sage · sage 200 spain4 Eki 2023
- CVE-2017-318336İzleyin
Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full access to pri
YüksekCVSS 8,8İstismar yokEPSS %2sage · xrt treasury24 Tem 2018
- CVE-2022-3432236İzleyin
Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the conte
KritikCVSS 9,0İstismar yokEPSS %1sage · sage enterprise intelligence1 Oca 2023
- CVE-2020-738732İzleyin
Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor
OrtaCVSS 5,3SilahlaştırılmışEPSS %36sage · adxadmin22 Tem 2021
- CVE-2024-4864632İzleyin
An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validatio
YüksekCVSS 8,1İstismar yokEPSS %1sage · sage frp 100030 Eki 2024
- CVE-2021-4549231İzleyin
In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the
YüksekCVSS 7,8İstismar yokEPSS %0sage · sage 30014 Tem 2022
- CVE-2022-3858331İzleyin
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configura
YüksekCVSS 7,8İstismar yokEPSS %0sage · sage 30028 Nis 2023
- CVE-2019-2505330İzleyin
A path traversal vulnerability exists in Sage FRP 1000 before November 2019.
YüksekCVSS 7,5İstismar yokEPSS %1sage · sage frp 100027 Oca 2023
- CVE-2022-4139930İzleyin
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decryp
YüksekCVSS 7,5İstismar yokEPSS %1sage · sage 30028 Nis 2023
- CVE-2022-4139830İzleyin
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr i
YüksekCVSS 7,5İstismar yokEPSS %1sage · sage 30028 Nis 2023
- CVE-2020-738929İzleyin
Sage X3 Syracuse Missing Authentication for Critical Function in Developer Environment
YüksekCVSS 7,2İstismar yokEPSS %2sage · syracuse22 Tem 2021
- CVE-2006-471228İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScri
OrtaCVSS 6,8İstismar yokEPSS %2sage · sage12 Eyl 2006
- CVE-2024-4864728İzleyin
A file disclosure vulnerability exists in Sage 1000 v7.0.0.
YüksekCVSS 7,2İstismar yokEPSS %1sage · sage frp 100030 Eki 2024
- CVE-2023-3186728İzleyin
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
YüksekCVSS 7,2İstismar yokEPSS %1sage · x322 Haz 2023
- CVE-2024-4864824İzleyin
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0.
OrtaCVSS 6,1İstismar yokEPSS %0sage · sage frp 100030 Eki 2024
- CVE-2003-124222İzleyin
Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path i
OrtaCVSS 5,0Kavram kanıtıEPSS %7sage · sage31 Ara 2003
- CVE-2020-739021İzleyin
Sage X3 Syracuse Persistent XSS in Edit User page
OrtaCVSS 5,4İstismar yokEPSS %1sage · syracuse22 Tem 2021
- CVE-2020-1389321İzleyin
Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web s
OrtaCVSS 5,4İstismar yokEPSS %1sage · easypay18 Eki 2020
- CVE-2022-3432321İzleyin
Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context
OrtaCVSS 5,4İstismar yokEPSS %0sage · sage xrt business exchange1 Oca 2023
- CVE-2023-3186821İzleyin
Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS).
OrtaCVSS 5,4İstismar yokEPSS %0sage · x322 Haz 2023
- CVE-2003-124318İzleyin
Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter
OrtaCVSS 4,3Kavram kanıtıEPSS %4sage · sage31 Ara 2003