Vendor: SAP | Product: NetWeaver | SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-9563 · CISA Known Exploited Vulnerabilities
Vendor: SAP | Product: NetWeaver | SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-6287 · CISA Known Exploited Vulnerabilities
Vendor: SAP | Product: NetWeaver | SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-6207 · CISA Known Exploited Vulnerabilities
Vendor: SAP | Product: Solution Manager | SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-3976 · CISA Known Exploited Vulnerabilities
Vendor: SAP | Product: NetWeaver | SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-16256 · CISA Known Exploited Vulnerabilities
Vendor: SIMalliance | Product: Toolbox Browser | SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-10148 · CISA Known Exploited Vulnerabilities
Vendor: SolarWinds | Product: Orion | SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-35211 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SonicWall Email Security | SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. | Required…
Read full source summary
Vendor: SonicWall | Product: SonicWall Email Security | SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-7481 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SMA100 | SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-20022 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SonicWall Email Security | SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. | Required action: Apply…
Read full source summary
Vendor: SonicWall | Product: SonicWall Email Security | SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-20023 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SonicWall Email Security | SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: SonicWall | Product: SonicWall Email Security | SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-20016 · CISA Known Exploited Vulnerabilities
Vendor: Sophos | Product: SFOS | Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access…
Read full source summary
Vendor: Sophos | Product: SFOS | Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-10181 · CISA Known Exploited Vulnerabilities
Vendor: Symantec | Product: Symantec Messaging Gateway | Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-18988 · CISA Known Exploited Vulnerabilities
Vendor: TeamViewer | Product: Desktop | TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system). |…
Read full source summary
Vendor: TeamViewer | Product: Desktop | TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-9248 · CISA Known Exploited Vulnerabilities
Vendor: Progress | Product: ASP.NET AJAX and Sitefinity | Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. | Required action: Apply…
Read full source summary
Vendor: Progress | Product: ASP.NET AJAX and Sitefinity | Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.