CVE-2022-24251
- EPSS 0.49%
- Veröffentlicht 01.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:02
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
CVE-2022-24252
- EPSS 2.16%
- Veröffentlicht 01.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:03
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.
CVE-2022-24253
- EPSS 0.49%
- Veröffentlicht 01.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:03
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
CVE-2022-24254
- EPSS 2.64%
- Veröffentlicht 01.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:03
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.
- EPSS 0.31%
- Veröffentlicht 01.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:03
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.