Vulnerabilities > Redhat > Interchange > 4.8.4

DATE CVE VULNERABILITY TITLE RISK
2020-05-15 CVE-2020-12685 Cross-site Scripting vulnerability in Redhat Interchange
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.
network
redhat CWE-79
4.3
2002-09-05 CVE-2002-0874 Denial-Of-Service vulnerability in Interchange
Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.
network
low complexity
redhat
5.0