CVE-2020-9351
- EPSS 0.87%
- Veröffentlicht 23.02.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 05:40:28
An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the _transaction parameter, the server replies with a verbose ...
CVE-2020-9352
- EPSS 1.06%
- Veröffentlicht 23.02.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 05:40:28
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: ...
CVE-2020-9353
- EPSS 0.82%
- Veröffentlicht 23.02.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 05:40:28
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL is affected by unauthenticated Local File Inclusion ...
CVE-2020-9354
- EPSS 0.79%
- Veröffentlicht 23.02.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 05:40:28
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite file...