2 results (0.010 seconds)

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

13 Dec 2022 — A vulnerability has been identified in Mendix Email Connector (All versions < V2.0.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read and manipulate sensitive information. Se ha identificado una vulnerabilidad en Mendix Email Connector (todas las versiones &lt; V2.0.0). Las versiones afectadas del módulo manejan incorrectamente el control de acceso para algunas entidades del módulo. • https://cert-portal.siemens.com/productcert/pdf/ssa-224632.pdf • CWE-284: Improper Access Control •

CVSS: 10.0EPSS: 94%CPEs: 398EXPL: 416

10 Dec 2021 — Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.... • https://packetstorm.news/files/id/171626 • CWE-20: Improper Input Validation CWE-400: Uncontrolled Resource Consumption CWE-502: Deserialization of Untrusted Data CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') •