Vulnerabilities (CVE)

Filtered by CWE-425
Total 163 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-18862 1 Bmc 2 Remedy Action Request System, Remedy Mid-tier 2019-10-03 6.5 MEDIUM 8.8 HIGH
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.
CVE-2017-2139 1 Frogman Office Inc 1 Cs-cart 2019-10-03 5.0 MEDIUM 5.3 MEDIUM
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.
CVE-2018-11346 1 Asustor 2 As6202t, As6202t Firmware 2019-10-03 4.0 MEDIUM 4.3 MEDIUM
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.