CVE-2021-45968
https://notcve.org/view.php?id=CVE-2021-45968
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394. Se ha detectado un problema en xmppserver jar en el componente XMPP Server de la plataforma JIve, tal como es usado en Pascom Cloud Phone System versiones anteriores a 7.20.x (y en otros productos). Un endpoint en el servidor Tomcat backend de Pascom permite una vulnerabilidad de tipo SSRF, un problema relacionado con CVE-2019-18394 • https://jivesoftware.com/platform https://kerbit.io/research/read/blog/4 https://tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.html https://www.pascom.net/doc/en/release-notes https://www.pascom.net/doc/en/release-notes/pascom19 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2016-4334
https://notcve.org/view.php?id=CVE-2016-4334
Jive before 2016.3.1 has an open redirect from the external-link.jspa page. Jive en versiones anteriores a 1.03.2016 tiene una redirección abierta desde la página external-link.jspa. • http://www.ericgoldman.name/en/2016/vulnerability-report-jive-open-redirect • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •