Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-10-05 CVE-2016-7561 Information Exposure vulnerability in Fortinet Fortiwlc
Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading the pam.log file.
network
low complexity
fortinet CWE-200
4.0
2016-10-05 CVE-2016-6652 SQL Injection vulnerability in Pivotal Software Spring Data JPA 1.10.2
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.
6.8
2016-10-05 CVE-2016-4551 Improper Access Control vulnerability in SAP Netweaver, SAP ABA and SAP Basis
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.
network
low complexity
sap CWE-284
5.0
2016-10-05 CVE-2016-1246 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.
network
low complexity
dbd-mysql-project perl debian CWE-119
5.0
2016-10-05 CVE-2016-8343 Path Traversal vulnerability in Indasengineering web Scada
Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
indasengineering CWE-22
5.0
2016-10-05 CVE-2016-6420 Permissions, Privileges, and Access Controls vulnerability in Cisco Firesight System Software
Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.
network
low complexity
cisco CWE-264
6.8
2016-10-05 CVE-2016-6419 SQL Injection vulnerability in Cisco Firepower Management Center
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
network
cisco CWE-89
6.0
2016-10-05 CVE-2016-5983 Improper Access Control vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
network
low complexity
ibm CWE-284
6.5
2016-10-05 CVE-2016-5084 Cryptographic Issues vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
animas CWE-310
5.0
2016-10-05 CVE-2016-4390 Remote Code Execution vulnerability in HP KeyView
The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4387, CVE-2016-4388, and CVE-2016-4389.
network
hp
6.8