Basware

Banking

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 31.08.2015 14:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to ...

  • EPSS 0.12%
  • Veröffentlicht 31.08.2015 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per A...

  • EPSS 0.05%
  • Veröffentlicht 31.08.2015 14:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 pe...

  • EPSS 0.44%
  • Veröffentlicht 31.08.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, which allows remote attackers to "disrupt security-critical functions" by "dropping network tr...

  • EPSS 0.19%
  • Veröffentlicht 31.08.2015 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT ...

  • EPSS 0.19%
  • Veröffentlicht 31.08.2015 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT...

  • EPSS 0.13%
  • Veröffentlicht 31.08.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffin...