Known Vulnerabilities for Adas by Prise
Listed below are 10 of the newest known vulnerabilities associated with "Adas" by "Prise".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-15089 json | An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the admini... | 8.8 - HIGH | 2019-09-20 | 2019-09-20 |
| CVE-2019-15088 json | An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific c... | 9.8 - CRITICAL | 2019-09-20 | 2020-08-24 |
| CVE-2019-15087 json | An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any func... | 7.2 - HIGH | 2019-09-20 | 2020-08-24 |
| CVE-2019-15086 json | An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in... | 6.1 - MEDIUM | 2019-09-20 | 2019-09-20 |
| CVE-2019-15085 json | An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form. | 7.5 - HIGH | 2019-09-20 | 2020-08-24 |
| CVE-2019-14916 json | An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload. | 6.5 - MEDIUM | 2019-09-20 | 2019-09-27 |
| CVE-2019-14915 json | An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submitting a r... | 6.1 - MEDIUM | 2019-09-20 | 2019-09-23 |
| CVE-2019-14914 json | An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to an arb... | 9.1 - CRITICAL | 2019-09-20 | 2019-09-23 |
| CVE-2019-14913 json | An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administrati... | 5.4 - MEDIUM | 2019-09-20 | 2019-09-23 |
| CVE-2019-14912 json | An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an ope... | 6.1 - MEDIUM | 2019-09-20 | 2019-09-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Prise | Adas | 1.7.0 |