Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-15 CVE-2018-7705 Path Traversal vulnerability in Securenvoy Securmail
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipients via a ..
network
low complexity
securenvoy CWE-22
8.1
2018-03-14 CVE-2018-2402 Information Exposure vulnerability in SAP Hana 1.00/2.00
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system.
network
low complexity
sap CWE-200
8.4
2018-03-14 CVE-2018-2401 XXE vulnerability in Redwood SAP Business Process Automation 9.00
SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability.
network
low complexity
redwood CWE-611
8.8
2018-03-14 CVE-2018-2400 Unspecified vulnerability in Redwood SAP Business Process Automation 9.00/9.10
Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted.
network
low complexity
redwood
7.5
2018-03-14 CVE-2018-2398 Unspecified vulnerability in SAP Business Client 6.5
Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
7.5
2018-03-14 CVE-2018-7533 Incorrect Default Permissions vulnerability in Osisoft PI Data Archive 2017/3.4.430.460
An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior.
local
low complexity
osisoft CWE-276
7.8
2018-03-14 CVE-2018-7529 Deserialization of Untrusted Data vulnerability in Osisoft PI Data Archive 3.4.430.460
A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior.
network
low complexity
osisoft CWE-502
7.5
2018-03-14 CVE-2018-1077 XXE vulnerability in Redhat Satellite and Spacewalk
Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.
network
low complexity
redhat CWE-611
7.5
2018-03-14 CVE-2018-1000121 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
network
low complexity
debian canonical haxx redhat oracle CWE-476
7.5
2018-03-14 CVE-2018-0983 Unspecified vulnerability in Microsoft Windows 10 and Windows Server 2016
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation of Privilege Vulnerability".
local
high complexity
microsoft
7.0