- EPSS 0.25%
- Veröffentlicht 31.08.2015 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to ...
CVE-2015-6746
- EPSS 0.12%
- Veröffentlicht 31.08.2015 14:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per A...
CVE-2015-6745
- EPSS 0.05%
- Veröffentlicht 31.08.2015 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 pe...
CVE-2015-6744
- EPSS 0.44%
- Veröffentlicht 31.08.2015 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, which allows remote attackers to "disrupt security-critical functions" by "dropping network tr...
CVE-2015-6743
- EPSS 0.19%
- Veröffentlicht 31.08.2015 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT ...
CVE-2015-6742
- EPSS 0.19%
- Veröffentlicht 31.08.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT...
CVE-2015-0943
- EPSS 0.13%
- Veröffentlicht 31.08.2015 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffin...