CVE-2020-3519
published 2020-08-26CVE-2020-3519: A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a…
PriorityP350high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
0.97%
57.7th percentile
A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_data_center_network_manager | — | — |
| cisco | data_center_network_manager | < 11.4\(1\) | 11.4\(1\) |
| cisco | data_center_network_manager_path | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
vendor_cisco5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pgmp-52m7-9hfg: A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to co
ghsa_unreviewed·2022-05-24
CVE-2020-3519 [MEDIUM] GHSA-pgmp-52m7-9hfg: A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to co
A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device.
Cisco
Cisco Data Center Network Manager Path Traversal Vulnerability
vendor_cisco·2020-08-19·CVSS 5.4
CVE-2020-3519 [MEDIUM] CWE-20 Cisco Data Center Network Manager Path Traversal Vulnerability
Cisco Data Center Network Manager Path Traversal Vulnerability
A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device.
The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-
Cisco
Cisco Data Center Network Manager Path Traversal Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3519 Cisco Data Center Network Manager Path Traversal Vulnerability
CVE-2020-3519: Cisco Data Center Network Manager Path Traversal Vulnerability
A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvt86736
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004169; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_t
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004168; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_11_19, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004167; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004164; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004166; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004165; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_A
No public exploits indexed.
Bugzilla
CVE-2020-2221 jenkins: Stored XSS vulnerability in upstream cause
bugzilla·2020-07-15·CVSS 5.4
CVE-2020-2221 [MEDIUM] CVE-2020-2221 jenkins: Stored XSS vulnerability in upstream cause
CVE-2020-2221 jenkins: Stored XSS vulnerability in upstream cause
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job’s display name shown as part of a build cause. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission.
References:
https://www.jenkins.io/security/advisory/2020-07-15/
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1857428]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3519 https://access.redhat.com/errata/RHSA-2020:3519
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2020-2223 jenkins: Stored XSS vulnerability in console links
bugzilla·2020-07-15·CVSS 5.4
CVE-2020-2223 [MEDIUM] CVE-2020-2223 jenkins: Stored XSS vulnerability in console links
CVE-2020-2223 jenkins: Stored XSS vulnerability in console links
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the href attribute of links to downstream jobs displayed in the build console page. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission.
References:
https://www.jenkins.io/security/advisory/2020-07-15/
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1857434]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3519 https://access.redhat.com/errata/RHSA-2020:3519
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat
Bugzilla
CVE-2020-2220 jenkins: Stored XSS vulnerability in job build time trend
bugzilla·2020-07-15·CVSS 5.4
CVE-2020-2220 [MEDIUM] CVE-2020-2220 jenkins: Stored XSS vulnerability in job build time trend
CVE-2020-2220 jenkins: Stored XSS vulnerability in job build time trend
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name on build time trend pages. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Agent/Configure permission.
References:
https://www.jenkins.io/security/advisory/2020-07-15/
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1857426]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3519 https://access.redhat.com/errata/RHSA-2020:3519
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-2220
Bugzilla
CVE-2020-2222 jenkins: Stored XSS vulnerability in 'keep forever' badge icons
bugzilla·2020-07-15·CVSS 5.4
CVE-2020-2222 [MEDIUM] CVE-2020-2222 jenkins: Stored XSS vulnerability in 'keep forever' badge icons
CVE-2020-2222 jenkins: Stored XSS vulnerability in 'keep forever' badge icons
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users able to configure job names.
References:
https://www.jenkins.io/security/advisory/2020-07-15/
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1857432]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3519 https://access.redhat.com/errata/RHSA-2020:3519
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securit
2020-08-26
Published