CVE-2024-7103 |
Description: A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the login flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser.
While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.
CVSS: MEDIUM (4.6) EPSS Score: 0.03% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-51553 |
Description: Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (6.5) EPSS Score: 0.03% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-51552 |
Description: Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (6.0) EPSS Score: 0.05% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-48848 |
Description: Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (6.5) EPSS Score: 0.04% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-13958 |
Description: Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (4.6) EPSS Score: 0.03% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-13956 |
Description: SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (6.7) EPSS Score: 0.05% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-13954 |
Description: Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (6.5) EPSS Score: 0.03% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-13953 |
Description: Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (4.9) EPSS Score: 0.04% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-13950 |
Description: Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (6.8) EPSS Score: 0.04% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|
CVE-2024-13949 |
Description: Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVSS: MEDIUM (6.9) EPSS Score: 0.03% SSVC Exploitation: none
May 22nd, 2025 (28 days ago)
|