2 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 2

MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme. MobileIron VSP versiones anteriores a 5.9.1 y Sentry versiones anteriores a 5.0, presentan un esquema de cifrado no seguro. • http://seclists.org/fulldisclosure/2014/Apr/21 https://www.securityfocus.com/archive/1/531713 • CWE-326: Inadequate Encryption Strength •

CVSS: 9.1EPSS: 18%CPEs: 2EXPL: 1

MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords MobileIron VSP versiones anteriores a la versión 5.9.1 y Sentry versiones anteriores a la versión 5.0, tienen una vulnerabilidad de omisión de autenticación debido a un archivo XML con contraseñas ofuscadas. MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 suffer from password obfuscation and XPath injection vulnerabilities. • http://seclists.org/fulldisclosure/2014/Apr/21 https://exchange.xforce.ibmcloud.com/vulnerabilities/92351 https://packetstormsecurity.com/files/cve/CVE-2014-1409 • CWE-91: XML Injection (aka Blind XPath Injection) •