Vulnerabilities > Atos

DATE CVE VULNERABILITY TITLE RISK
2020-02-21 CVE-2019-19866 Authorization Bypass Through User-Controlled Key vulnerability in Atos Unify Openscape UC web Client 10.0/9.0
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information.
network
low complexity
atos CWE-639
7.5
2020-02-21 CVE-2019-19865 Cross-site Scripting vulnerability in Atos Unify Openscape UC web Client 1.0
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS.
network
low complexity
atos CWE-79
6.1
2020-01-09 CVE-2014-2651 Improper Authentication vulnerability in Atos products
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
network
low complexity
atos CWE-287
critical
9.8
2020-01-09 CVE-2014-2650 OS Command Injection vulnerability in Atos products
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
network
low complexity
atos CWE-78
critical
9.8