CVE-2023-50101 |
|
CVE-2023-50089 |
|
CVE-2023-50038 |
|
CVE-2023-49999 |
|
CVE-2023-49991 |
|
CVE-2023-49706 |
Description: Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.
CVSS: LOW (0.0) EPSS Score: 0.19%
November 27th, 2024 (6 months ago)
|
CVE-2023-49587 |
Description: SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without user interaction over the network.
CVSS: MEDIUM (6.4) EPSS Score: 0.05%
November 27th, 2024 (6 months ago)
|
CVE-2023-49490 |
|
CVE-2023-49462 |
|
CVE-2023-49432 |
|