CVE-2020-29022 – Host Header Injection allowing web cache poisoning attacks
https://notcve.org/view.php?id=CVE-2020-29022
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3 Un fallo en la saneamiento del valor del encabezado del host en la salida del servidor web GateManager, podría permitir a un atacante conducir ataques de envenenamiento de la caché web. Este problema afecta a Secomea GateManager todas las versiones anteriores a 9.3 • https://www.secomea.com/support/cybersecurity-advisory/#2923 • CWE-159: Improper Handling of Invalid Use of Special Elements •
CVE-2020-29024 – Missing HtppOnly and Secure flags
https://notcve.org/view.php?id=CVE-2020-29024
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3. Una Vulnerabilidad de Cookie Confidencial en la sesión HTTPS sin el Atributo "Secure" en (GTA) GoToAppliance de Secomea GateManager, podría permitir a un atacante conseguir acceso a cookies confidenciales. Este problema afecta: Secomea GateManager todas las versiones anteriores a 9.3 • https://www.secomea.com/support/cybersecurity-advisory/#2418 • CWE-311: Missing Encryption of Sensitive Data CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute •
CVE-2020-29031 – Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
https://notcve.org/view.php?id=CVE-2020-29031
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c Se presenta una vulnerabilidad de Referencia Directa a Objetos No Segura en la Interfaz de Usuario Web de GateManager que permite a un atacante autenticado restablecer la contraseña de cualquier usuario en su dominio o subdominio, por medio de una escalada de privilegios. Este problema afecta a todas las versiones de GateManager anteriores a 9.2c • https://www.secomea.com/support/cybersecurity-advisory/#2920 • CWE-269: Improper Privilege Management CWE-280: Improper Handling of Insufficient Permissions or Privileges •
CVE-2020-29026
https://notcve.org/view.php?id=CVE-2020-29026
A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c. Se presenta una vulnerabilidad de salto de directorio en la función file upload del GateManager que permite a un atacante autenticado con permisos administrativos leer y escribir archivos arbitrarios en el sistema de archivos de Linux. Este problema afecta a: GateManager todas las versiones anteriores a 9.2c • https://www.secomea.com/support/cybersecurity-advisory/#2918 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-29021 – Scripting tag chars < > not filtered in input fields could cause Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2020-29021
A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3. Una vulnerabilidad en el campo de entrada de la interfaz de Usuario Web de GateManager, permite a un atacante autenticado ingresar etiquetas de script que podrían causar un ataque de tipo XSS. Este problema afecta a: GateManager todas las versiones anteriores a 9.3 • https://www.secomea.com/support/cybersecurity-advisory • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •