- EPSS 1.01%
- Veröffentlicht 13.08.2025 16:51:26
- Zuletzt bearbeitet 13.02.2026 18:16:10
Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031 with the U...
CVE-2022-23342
- EPSS 0.54%
- Veröffentlicht 21.06.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:26
The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for inv...
CVE-2020-25258
- EPSS 0.41%
- Veröffentlicht 11.09.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:17:47
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses ASP.NET BinaryFormatter.Deserialize in a manner that allows attackers to transmit and ...
CVE-2020-25259
- EPSS 0.33%
- Veröffentlicht 11.09.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:17:47
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses XML deserialization libraries in an unsafe manner.
CVE-2020-25260
- EPSS 2.12%
- Veröffentlicht 11.09.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:17:47
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attackers to execute arbitrary code because of unsafe JSON deserialization.
CVE-2020-25247
- EPSS 0.6%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:45
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.
CVE-2020-25248
- EPSS 0.37%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:45
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Directory traversal exists for reading files, as demonstrated by the FileName paramete...
CVE-2020-25249
- EPSS 0.24%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:45
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. The server typically logs activity only when a client application specifies that logging is de...
CVE-2020-25250
- EPSS 0.24%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:45
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client applications can write arbitrary data to the server logs.
CVE-2020-25251
- EPSS 0.25%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:46
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client-side authentication is used for critical functions such as adding users or retrieving s...