3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-26819
SAP NetWeaver AS ABAP (Web Dynpro) General
5.4
MEDIUM
EPSS
0.4%
2020 1 PoC

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.

CVE-2020-35509
keycloak General
5.4
MEDIUM
EPSS
0.1%
2020 CWE-20 1 PoC

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2020-6301
SAP ERP (HCM Travel Management) General
5.4
MEDIUM
EPSS
0.2%
2020 1 PoC

SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check.

CVE-2020-10135
BR/EDR General
5.4
MEDIUM
EPSS
20.2%
2020 CWE-757 4 PoCs

Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.

CVE-2020-11918
Software Genérico General
5.4
MEDIUM
EPSS
0.0%
2020 1 PoC

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file.

CVE-2020-6199
SAP ERP (EAPPGLO) General
5.4
MEDIUM
EPSS
0.1%
2020 1 PoC

The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization group can maintain any company certificate, leading to Missing Authorization Check.

CVE-2020-6212
SAP ERP General
5.4
MEDIUM
EPSS
0.1%
2020 1 PoC

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax reports, due to Missing Authorization Check.

CVE-2020-7685
UmbracoForms General
5.4
MEDIUM
EPSS
0.2%
2020 1 PoC

This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.

CVE-2020-1768
OTRS General
5.4
MEDIUM
EPSS
0.3%
2020 CWE-613 1 PoC

The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.

CVE-2020-4188
Security Guardium General
5.3
MEDIUM
EPSS
0.3%
2020 1 PoC

IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.

CVE-2020-8867
UA .NET Standard General
5.3
MEDIUM
EPSS
1.7%
2020 CWE-367 1 PoC

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to create a denial-of-service condition against the application. Was ZDI-CAN-10295.

CVE-2020-35460
Software Genérico General
5.3
MEDIUM
EPSS
0.5%
2020 2 PoCs

common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

CVE-2020-4576
WebSphere Application Server General
5.3
MEDIUM
EPSS
0.4%
2020 1 PoC

IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.

CVE-2020-10958
Software Genérico General
5.3
MEDIUM
EPSS
0.5%
2020 2 PoCs

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

CVE-2020-11081
osquery General
5.3
MEDIUM
EPSS
0.1%
2020 CWE-114 1 PoC

osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.

CVE-2020-28493
jinja2 General
5.3
MEDIUM
EPSS
0.2%
2020 1 PoC

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CVE-2020-8476
Central Licensing System General
5.3
MEDIUM
EPSS
0.3%
2020 CWE-20 1 PoC

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 an

CVE-2020-7767
express-validators General
5.3
MEDIUM
EPSS
0.4%
2020 1 PoC

All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls.

CVE-2020-6240
SAP NetWeaver AS ABAP (Web Dynpro ABAP) (SAP_UI) General
5.3
MEDIUM
EPSS
1.4%
2020 1 PoC

SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service

CVE-2020-29507
Dell BSAFE Crypto-C Micro Edition General
5.3
MEDIUM
EPSS
1.1%
2020 CWE-20 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability.