Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-26 CVE-2017-15917 Improper Privilege Management vulnerability in Paessler Prtg Network Monitor 17.3.33.2830
In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.
network
low complexity
paessler CWE-269
6.5
2017-10-26 CVE-2017-15911 Cross-site Scripting vulnerability in Igniterealtime Openfire
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS.
network
low complexity
igniterealtime CWE-79
4.8
2017-10-26 CVE-2017-12158 Cross-site Scripting vulnerability in multiple products
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations.
network
low complexity
redhat keycloak CWE-79
5.4
2017-10-26 CVE-2017-7732 Cross-site Scripting vulnerability in Fortinet Fortimail
A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail login page allows attacker to inject arbitrary web script or HTML via crafted HTTP requests.
network
low complexity
fortinet CWE-79
6.1
2017-10-26 CVE-2017-7335 Cross-site Scripting vulnerability in Fortinet Fortiwlc
A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows an authenticated user to inject arbitrary web script or HTML via non-sanitized parameters "refresh" and "branchtotable" present in HTTP POST requests.
network
low complexity
fortinet CWE-79
5.4
2017-10-26 CVE-2017-15906 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
network
low complexity
openbsd oracle debian netapp redhat CWE-732
5.3
2017-10-25 CVE-2017-1363 Cross-site Scripting vulnerability in IBM Rational Collaborative Lifecycle Management
IBM Team Concert (RTC) is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-25 CVE-2017-1295 Information Exposure vulnerability in IBM Rational Collaborative Lifecycle Management
IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage.
network
low complexity
ibm CWE-200
4.3
2017-10-25 CVE-2017-1241 Information Exposure vulnerability in IBM Rational Collaborative Lifecycle Management
An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace information to an attacker.
network
low complexity
ibm CWE-200
4.3
2017-10-25 CVE-2017-1169 Cross-site Scripting vulnerability in IBM Rational Collaborative Lifecycle Management
IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4