Lucene search

K

Jedox Security Vulnerabilities

cve
cve

CVE-2022-47879

A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its...

7.5CVSS

7.6AI Score

0.009EPSS

2023-05-12 02:15 PM
14
cve
cve

CVE-2022-47880

An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection'...

5.3CVSS

5AI Score

0.004EPSS

2023-05-12 02:15 PM
11
cve
cve

CVE-2022-47875

A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary...

8.8CVSS

8.6AI Score

0.02EPSS

2023-05-02 08:15 PM
16
cve
cve

CVE-2022-47874

Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method...

6.5CVSS

6.5AI Score

0.023EPSS

2023-05-02 08:15 PM
13
cve
cve

CVE-2022-47876

The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via...

8.8CVSS

8.7AI Score

0.046EPSS

2023-05-02 08:15 PM
13
cve
cve

CVE-2022-47878

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary...

8.8CVSS

8.7AI Score

0.019EPSS

2023-05-02 08:15 PM
11
cve
cve

CVE-2022-47877

A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module...

5.4CVSS

5AI Score

0.001EPSS

2023-05-02 08:15 PM
15
cve
cve

CVE-2007-3581

The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel with the Palo plugin, opening a cube, and performing an Insert...

6.8AI Score

0.004EPSS

2007-07-05 08:30 PM
24