CVE-2020-25252
- EPSS 0.16%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:46
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default...
CVE-2020-25253
- EPSS 0.26%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:46
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by the TableName, ColumnName, Name, UserId, or Passwo...
CVE-2020-25254
- EPSS 0.32%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:46
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by TestConnection_LocalOrLinkedServer, CreateFilterFr...
CVE-2020-25255
- EPSS 0.56%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:46
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attackers to cause a denial of service (outage of connection-request processi...
CVE-2020-25256
- EPSS 0.14%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:47
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across different customers' installations...
CVE-2020-25257
- EPSS 0.36%
- Veröffentlicht 11.09.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:47
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files.