Lucene search

K

MDM Security Vulnerabilities

cve
cve

CVE-2023-47312

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit...

6.5CVSS

6.5AI Score

0.0005EPSS

2023-11-22 05:15 PM
13
cve
cve

CVE-2023-47315

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied...

8.8CVSS

8.6AI Score

0.001EPSS

2023-11-22 05:15 PM
8
cve
cve

CVE-2023-47313

Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal. The application uses an API call to move the uploaded temporary file to the file directory during the file upload process. This API call receives two input parameters, such as path and localPath. The first one refers to the...

5.4CVSS

5.6AI Score

0.0005EPSS

2023-11-22 05:15 PM
9
cve
cve

CVE-2023-47316

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API...

5.4CVSS

5.7AI Score

0.0004EPSS

2023-11-22 05:15 PM
7
cve
cve

CVE-2023-47314

Headwind MDM Web panel 5.22.1 is vulnerable to cross-site scripting (XSS). The file upload function allows APK and arbitrary files to be uploaded. By exploiting this issue, attackers may upload HTML files and share the download URL pointing to these files with the victims. As the file download...

5.4CVSS

5.3AI Score

0.0004EPSS

2023-11-22 05:15 PM
10
cve
cve

CVE-2023-41344

NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system...

7.5CVSS

7.7AI Score

0.001EPSS

2023-11-03 07:15 AM
36
cve
cve

CVE-2021-4311

A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. It is recommended...

9.8CVSS

9.5AI Score

0.002EPSS

2023-01-09 12:15 PM
23
cve
cve

CVE-2022-4818

A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external entity reference....

5.5CVSS

4.8AI Score

0.001EPSS

2022-12-28 09:15 PM
29
cve
cve

CVE-2010-4741

Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to execute arbitrary code via crafted data in a session on TCP port...

8.1AI Score

0.332EPSS

2022-10-03 04:21 PM
43
cve
cve

CVE-2019-11212

The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions;...

6.3CVSS

5.4AI Score

0.001EPSS

2019-10-09 04:15 PM
15
cve
cve

CVE-2019-0361

SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)...

6.1CVSS

5.9AI Score

0.001EPSS

2019-09-10 05:15 PM
33
cve
cve

CVE-2018-2448

Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be...

5.3CVSS

5.1AI Score

0.001EPSS

2018-08-14 04:29 PM
23
cve
cve

CVE-2018-2449

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB...

8.6CVSS

8.7AI Score

0.003EPSS

2018-08-14 04:29 PM
31
cve
cve

CVE-2014-1663

Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown...

6.3AI Score

0.005EPSS

2014-02-06 05:00 PM
22