Vulnerabilities > Basware

DATE CVE VULNERABILITY TITLE RISK
2015-08-31 CVE-2015-6747 Information Exposure vulnerability in Basware Banking
Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors.
network
low complexity
basware CWE-200
5.0
2015-08-31 CVE-2015-6746 Information Exposure vulnerability in Basware Banking
Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications with banks via unspecified vectors.
local
low complexity
basware CWE-200
2.1
2015-08-31 CVE-2015-6745 Permissions, Privileges, and Access Controls vulnerability in Basware Banking
Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table.
local
low complexity
basware CWE-264
4.6
2015-08-31 CVE-2015-6744 Unspecified vulnerability in Basware Banking
Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, which allows remote attackers to "disrupt security-critical functions" by "dropping network traffic." NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions.
network
basware
4.3
2015-08-31 CVE-2015-6743 Credentials Management vulnerability in Basware Banking
Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.
network
low complexity
basware CWE-255
6.5
2015-08-31 CVE-2015-6742 Credentials Management vulnerability in Basware Banking
Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.
network
low complexity
basware CWE-255
6.5
2015-08-31 CVE-2015-0943 Information Exposure vulnerability in Basware Banking
Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream.
network
basware CWE-200
5.8