Vulnerabilities > Fico
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-09 | CVE-2023-30056 | Session Fixation vulnerability in Fico Origination Manager Decision 4.8.1 A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie. | 7.5 |
2023-05-09 | CVE-2023-30057 | Cross-site Scripting vulnerability in Fico Origination Manager Decision 4.8.1 Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload. | 5.4 |