PriseCVEs & Vulnerabilities

11 CVEs affecting Prise products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

adas 11
CVE-2019-15089HIGH

An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator.

20 Sep 2019
8.8
CVSS
CVE-2019-15088CRITICAL

An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.

20 Sep 2019
9.8
CVSS
CVE-2019-15087HIGH

An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution.

20 Sep 2019
7.2
CVSS
CVE-2019-15086MEDIUM

An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message.

20 Sep 2019
6.1
CVSS
CVE-2019-15085HIGH

An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form.

20 Sep 2019
7.5
CVSS
CVE-2019-14916MEDIUM

An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload.

20 Sep 2019
6.5
CVSS
CVE-2019-14915MEDIUM

An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submitting a rogue certificate.

20 Sep 2019
6.1
CVSS
CVE-2019-14914CRITICAL

An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to an arbitrary file read and deletion via Directory Traversal.

20 Sep 2019
9.1
CVSS
CVE-2019-14913MEDIUM

An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administration panel.

20 Sep 2019
5.4
CVSS
CVE-2019-14912MEDIUM

An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.

20 Sep 2019
6.1
CVSS
CVE-2019-14911MEDIUM

An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to reflected XSS.

20 Sep 2019
6.1
CVSS
← PrevPage 1 / 1Next →
Prise CVEs & Vulnerabilities — 11 Tracked