CVE-2020-4251
published 2020-06-12CVE-2020-4251: IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.56%
42.7th percentile
IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175489.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | api_connect | — | — |
| ibm | api_connect | — | — |
| ibm | api_connect | 5.0.0.0 – 5.0.8.8 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9746 flash-plugin: Arbitrary Code Execution vulnerability (APSB20-58)
bugzilla·2020-10-13·CVSS 7.0
CVE-2020-9746 [HIGH] CVE-2020-9746 flash-plugin: Arbitrary Code Execution vulnerability (APSB20-58)
CVE-2020-9746 flash-plugin: Arbitrary Code Execution vulnerability (APSB20-58)
Adobe Security Bulletin APSB20-58 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
NULL Pointer Dereference -- CVE-2020-9746
Adobe Security Bulletin also notes:
Exploitation of CVE-2020-9746 requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4251 https://access.redhat.com/errata/RHSA-2020:4251
---
This bug is now closed. Furt
Bugzilla
CVE-2020-15389 openjpeg: use-after-free and double-free via a mix of valid and invalid files in a directory operated on by the decompressor
bugzilla·2020-07-01·CVSS 6.5
CVE-2020-15389 [MEDIUM] CVE-2020-15389 openjpeg: use-after-free and double-free via a mix of valid and invalid files in a directory operated on by the decompressor
CVE-2020-15389 openjpeg: use-after-free and double-free via a mix of valid and invalid files in a directory operated on by the decompressor
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
Reference:
https://github.com/uclouvain/openjpeg/issues/1261
Discussion:
Created openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1852871]
Created openjpeg2 tracking bugs for this issue:
Affects: epel-all [bug 1852870]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:4251 https://access.redhat.com
2020-06-12
Published