CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning of streaming cubes, creation/modification and deletion of replica sets, to the Kylin Coordinator. For endpoints accepting node details in HTTP message body, unauthenticated (but limited) server-side request forgery (SSRF) can be achieved. This issue affects Apache Kylin Apache Kylin 3 versions prior to 3.1.2.
Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
File_transfer_appliance, Fta, Ftp_server, Kiteworks, Kiteworks_appliance, Managed_file_transfer, Secure_file_transfer_appliance
2021-03-05
N/A
6.1 MEDIUM
Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later.
File_transfer_appliance, Fta, Ftp_server, Kiteworks, Kiteworks_appliance, Managed_file_transfer, Secure_file_transfer_appliance
2021-03-05
N/A
9.8 CRITICAL
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.
