BpcbtCVEs & Vulnerabilities

11 CVEs affecting Bpcbt products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

smartvista 6smartvista front-end 3smartvista cardgen 2
CVE-2022-38619CRITICAL

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.

21 Sep 2022
9.8
CVSS
CVE-2022-38618HIGH

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.

19 Sep 2022
8.8
CVSS
CVE-2022-38617HIGH

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.

19 Sep 2022
8.8
CVSS
CVE-2022-38616HIGH

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.

13 Sep 2022
8.8
CVSS
CVE-2022-38615HIGH

SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.

9 Sep 2022
8.8
CVSS
CVE-2022-38614HIGH

An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.

9 Sep 2022
7.5
CVSS
CVE-2022-38613MEDIUM

A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.

9 Sep 2022
6.5
CVSS
CVE-2022-35554MEDIUM

Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side.

20 Aug 2022
6.1
CVSS
CVE-2018-15208HIGH

BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.

30 Apr 2019
7.5
CVSS
CVE-2018-15207HIGH

BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.

30 Apr 2019
7.2
CVSS
CVE-2018-15206HIGH

BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.

30 Apr 2019
8.8
CVSS
← PrevPage 1 / 1Next →
Bpcbt CVEs & Vulnerabilities — 11 Tracked