CVE-2021-35483
- EPSS 0.03%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 05.03.2026 21:50:19
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a...
- EPSS 0.03%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 05.03.2026 21:53:44
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the...
CVE-2021-35486
- EPSS 0.02%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 13.03.2026 01:04:48
A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X...
CVE-2023-31044
- EPSS 0.04%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 09.03.2026 13:38:49
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV f...
CVE-2021-35484
- EPSS 0.03%
- Veröffentlicht 03.03.2026 00:00:00
- Zuletzt bearbeitet 05.03.2026 21:53:00
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET param...
CVE-2019-17406
- EPSS 0.44%
- Veröffentlicht 25.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 04:32:16
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
CVE-2019-17403
- EPSS 4.37%
- Veröffentlicht 25.11.2019 15:15:35
- Zuletzt bearbeitet 21.11.2024 04:32:16
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
CVE-2019-17404
- EPSS 0.27%
- Veröffentlicht 25.11.2019 15:15:35
- Zuletzt bearbeitet 21.11.2024 04:32:16
Nokia IMPACT < 18A: allows full path disclosure
CVE-2019-17405
- EPSS 0.35%
- Veröffentlicht 25.11.2019 15:15:35
- Zuletzt bearbeitet 21.11.2024 04:32:16
Nokia IMPACT < 18A: has Reflected self XSS