Lucene search

K

Impact Security Vulnerabilities

cve
cve

CVE-2021-29794

IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID:...

7.5CVSS

7.2AI Score

0.001EPSS

2021-07-12 04:15 PM
23
4
cve
cve

CVE-2020-4849

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID:...

6.1CVSS

6.1AI Score

0.001EPSS

2020-12-15 03:15 PM
22
2
cve
cve

CVE-2019-12783

An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site,.....

6.1CVSS

7.1AI Score

0.001EPSS

2020-07-14 08:15 PM
21
cve
cve

CVE-2019-12784

An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them to guess and...

8.8CVSS

6.3AI Score

0.001EPSS

2020-07-14 08:15 PM
21
cve
cve

CVE-2019-12773

An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scripts or phishing pages on a site where this...

6.1CVSS

6.2AI Score

0.001EPSS

2020-07-14 08:15 PM
16
cve
cve

CVE-2020-4238

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID:...

8.8CVSS

8.4AI Score

0.001EPSS

2020-03-31 03:15 PM
33
cve
cve

CVE-2020-4239

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID:...

5.3CVSS

4.8AI Score

0.001EPSS

2020-03-31 03:15 PM
29
cve
cve

CVE-2020-4236

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to improper content parsing in the project management module. IBM X-Force ID:...

6.5CVSS

6.2AI Score

0.001EPSS

2020-03-31 03:15 PM
29
cve
cve

CVE-2020-4237

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID:...

8.8CVSS

8.4AI Score

0.001EPSS

2020-03-31 03:15 PM
28
cve
cve

CVE-2020-4235

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force...

5.4CVSS

5.2AI Score

0.001EPSS

2020-03-31 03:15 PM
28
cve
cve

CVE-2019-4681

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force...

6.1CVSS

5.8AI Score

0.001EPSS

2020-03-24 04:15 PM
17
cve
cve

CVE-2019-17406

Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with...

5.3CVSS

6.5AI Score

0.004EPSS

2019-11-25 04:15 PM
20
cve
cve

CVE-2019-17403

Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code...

8.8CVSS

8.7AI Score

0.01EPSS

2019-11-25 03:15 PM
21
cve
cve

CVE-2019-17405

Nokia IMPACT < 18A: has Reflected self...

6.1CVSS

5.9AI Score

0.001EPSS

2019-11-25 03:15 PM
22
cve
cve

CVE-2019-17404

Nokia IMPACT < 18A: allows full path...

4.3CVSS

4.5AI Score

0.001EPSS

2019-11-25 03:15 PM
21
cve
cve

CVE-2019-4570

IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID:...

5.3CVSS

5AI Score

0.001EPSS

2019-11-22 04:15 PM
35
cve
cve

CVE-2019-4569

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force...

5.4CVSS

5.2AI Score

0.001EPSS

2019-11-22 04:15 PM
35
cve
cve

CVE-2019-4103

IBM Tivoli Netcool/Impact 7.1.0 allows for remote execution of command by low privileged User. Remote code execution allow to execute arbitrary code on system which lead to take control over the system. IBM X-Force ID:...

8CVSS

8.2AI Score

0.004EPSS

2019-06-17 03:15 PM
47
cve
cve

CVE-2017-5712

Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution...

7.2CVSS

7.5AI Score

0.012EPSS

2017-11-21 02:29 PM
145
cve
cve

CVE-2017-5711

Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution...

7.8CVSS

7.4AI Score

0.0004EPSS

2017-11-21 02:29 PM
34
cve
cve

CVE-2014-6161

Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool/Impact 6.1.1 before 6.1.1.1-TIV-NCI-IF0001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted...

5.2AI Score

0.001EPSS

2014-11-08 11:55 AM
20
cve
cve

CVE-2010-2332

Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST...

6.8AI Score

0.019EPSS

2010-06-18 08:30 PM
19
cve
cve

CVE-2008-5733

SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id...

8.4AI Score

0.001EPSS

2008-12-26 05:30 PM
23