Tufin

Securetrack

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 09.02.2021 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:18

Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.

  • EPSS 0.15%
  • Veröffentlicht 09.02.2021 05:15:13
  • Zuletzt bearbeitet 21.11.2024 05:01:11

Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and re...

  • EPSS 0.15%
  • Veröffentlicht 09.02.2021 05:15:13
  • Zuletzt bearbeitet 21.11.2024 05:01:11

Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and re...

  • EPSS 0.14%
  • Veröffentlicht 09.02.2021 05:15:13
  • Zuletzt bearbeitet 21.11.2024 05:01:18

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.

  • EPSS 0.08%
  • Veröffentlicht 09.02.2021 05:15:13
  • Zuletzt bearbeitet 21.11.2024 05:01:18

Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of...

  • EPSS 0.15%
  • Veröffentlicht 09.02.2021 05:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:11

Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and re...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 19.06.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 03:55:52

An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The ...