Known Vulnerabilities for products from Sapphireims

Listed below are 11 of the newest known vulnerabilities associated with the vendor "Sapphireims".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-25566 json In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. No... 9.8 - CRITICAL 2021-08-11 2022-07-12
CVE-2020-25565 json In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain ac... 9.8 - CRITICAL 2021-08-11 2021-08-17
CVE-2020-25564 json In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by d... 8.8 - HIGH 2021-08-11 2022-07-12
CVE-2020-25563 json In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly ... 9.8 - CRITICAL 2021-08-11 2021-08-16
CVE-2020-25562 json In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critic... 6.5 - MEDIUM 2021-08-11 2021-08-16
CVE-2020-25561 json SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerCo... 7.8 - HIGH 2021-08-11 2021-08-16
CVE-2020-25560 json In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain ac... 9.8 - CRITICAL 2021-08-11 2022-06-28
CVE-2017-16632 json In SapphireIMS 4097_1, the password in the database is stored in Base64 format. 7.5 - HIGH 2021-08-11 2021-08-16
CVE-2017-16631 json In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Direct ... 6.5 - MEDIUM 2021-08-11 2021-08-16
CVE-2017-16630 json In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, be... 8.8 - HIGH 2021-08-11 2021-08-16
CVE-2017-16629 json In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives out f... 7.5 - HIGH 2021-08-11 2021-08-12

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report