CVE-2024-32014
- EPSS 0.01%
- Veröffentlicht 11.11.2025 20:20:19
- Zuletzt bearbeitet 12.11.2025 16:19:12
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local database which contains the application credentials. This allows an attacker to gain administrativ...
CVE-2024-32011
- EPSS 0.07%
- Veröffentlicht 11.11.2025 20:20:18
- Zuletzt bearbeitet 12.11.2025 16:19:12
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the exec...
CVE-2024-32010
- EPSS 0.01%
- Veröffentlicht 11.11.2025 20:20:16
- Zuletzt bearbeitet 12.11.2025 16:19:12
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the...
CVE-2024-32009
- EPSS 0.01%
- Veröffentlicht 11.11.2025 20:20:15
- Zuletzt bearbeitet 12.11.2025 16:19:12
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to wrongly set permissions to a binary which allows any local attacker to gain ad...
CVE-2024-32008
- EPSS 0.01%
- Veröffentlicht 11.11.2025 20:20:13
- Zuletzt bearbeitet 12.11.2025 16:19:12
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gai...
CVE-2022-26476
- EPSS 0.25%
- Veröffentlicht 14.06.2022 10:15:19
- Zuletzt bearbeitet 21.11.2024 06:54:01
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component S...
CVE-2022-23312
- EPSS 0.53%
- Veröffentlicht 09.02.2022 16:15:15
- Zuletzt bearbeitet 21.11.2024 06:48:23
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP9 Security Patch 1). The integrated web application "Online Help" in affected product contains a Cross-Site Scripting (XSS) vulnerability that could be exploited if unsus...
- EPSS 94.34%
- Veröffentlicht 14.12.2021 19:15:07
- Zuletzt bearbeitet 27.10.2025 17:35:56
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a n...
- EPSS 94.36%
- Veröffentlicht 10.12.2021 10:15:09
- Zuletzt bearbeitet 27.10.2025 17:40:33
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...
CVE-2020-15790
- EPSS 0.24%
- Veröffentlicht 09.09.2020 19:15:20
- Zuletzt bearbeitet 21.11.2024 05:06:11
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.