Tenable

Tenable.Sc

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 01.02.2023 03:15:08
  • Zuletzt bearbeitet 27.03.2025 15:15:42

As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to e...

  • EPSS 0.11%
  • Veröffentlicht 26.01.2023 21:18:19
  • Zuletzt bearbeitet 27.03.2025 20:15:19

A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interact with external and internal services covertly.

  • EPSS 0.26%
  • Veröffentlicht 26.01.2023 21:18:19
  • Zuletzt bearbeitet 01.04.2025 15:15:58

A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a user to click a specially crafte...

  • EPSS 0.16%
  • Veröffentlicht 26.01.2023 21:18:19
  • Zuletzt bearbeitet 01.04.2025 15:15:58

A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system to export reports containing formulas, which would th...

  • EPSS 0.24%
  • Veröffentlicht 26.01.2023 21:18:09
  • Zuletzt bearbeitet 01.04.2025 15:15:58

A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP inj...

  • EPSS 0.22%
  • Veröffentlicht 13.04.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:11

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads t...

  • EPSS 0.61%
  • Veröffentlicht 04.04.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:05

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string ...

  • EPSS 1.94%
  • Veröffentlicht 14.01.2022 20:15:15
  • Zuletzt bearbeitet 21.11.2024 06:37:57

Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific f...

Exploit
  • EPSS 87.09%
  • Veröffentlicht 20.12.2021 12:15:07
  • Zuletzt bearbeitet 01.05.2025 15:38:06

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This...

  • EPSS 10.7%
  • Veröffentlicht 20.12.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:37

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix D...