cbcvebase.

Netgain-Systems Enterprise Manager vulnerabilities

25 known vulnerabilities affecting netgain-systems/enterprise_manager.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH8MEDIUM12

Vulnerabilities

Page 1 of 2
CVE-2017-16608P1CRITICALCVSS 9.8Exploitedfixed in 7.2.7662018-01-23
CVE-2017-16608 [CRITICAL] CWE-78 CVE-2017-16608: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call
nvd
CVE-2017-16602P1HIGHCVSS 8.8Exploitedv7.2.7302018-01-23
CVE-2017-16602 [HIGH] CWE-78 CVE-2017-16602: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.tools.exec_jsp servle
nvd
CVE-2017-16597P2CRITICALCVSS 9.8v7.2.7302018-01-23
CVE-2017-16597 [CRITICAL] CWE-22 CVE-2017-16597: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of WRQ requests. When parsing the Filename field, the process does not properly validat
nvd
CVE-2017-16603P2HIGHCVSS 8.8v7.2.7302018-01-23
CVE-2017-16603 [HIGH] CWE-22 CVE-2017-16603: This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.se
nvd
CVE-2017-16610P2CRITICALCVSS 9.8fixed in 7.2.7662018-01-23
CVE-2017-16610 [CRITICAL] CWE-22 CVE-2017-16610: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operat
nvd
CVE-2017-17407P2CRITICALCVSS 9.8v7.2.6992018-01-23
CVE-2017-17407 [CRITICAL] CWE-78 CVE-2017-17407: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the content parameter provided to the script_test.jsp endpoint. A crafted content req
nvd
CVE-2017-17406P2CRITICALCVSS 9.8fixed in 7.2.7662018-01-23
CVE-2017-17406 [CRITICAL] CWE-502 CVE-2017-17406: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within an exposed RMI registry, which listens on TCP ports 1800 and 1850 by default. The issue results from the lack of proper validati
nvd
CVE-2017-16598P2HIGHCVSS 8.8v7.2.7302018-01-23
CVE-2017-16598 [HIGH] CWE-22 CVE-2017-16598: This vulnerability allows remote attackers to execute code by overwriting arbitrary files on vulnera This vulnerability allows remote attackers to execute code by overwriting arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp
nvd
CVE-2017-16606P2HIGHCVSS 8.8v7.2.7302018-01-23
CVE-2017-16606 [HIGH] CWE-22 CVE-2017-16606: This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp._3
nvd
CVE-2017-16590P3HIGHCVSS 8.8v7.2.6992018-01-23
CVE-2017-16590 [HIGH] CWE-289 CVE-2017-16590: This vulnerability allows remote attackers to bypass authentication on vulnerable installations of N This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1001. User interaction is required to exploit this vulnerability. The specific flaw exists within the MainFilter servlet. The issue results from the lack of proper string matching inside the doFilter metho
nvd
CVE-2017-16609P3HIGHCVSS 7.5fixed in 7.2.7662018-01-23
CVE-2017-16609 [HIGH] CWE-39 CVE-2017-16609: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a f
nvd
CVE-2018-10587P3HIGHCVSS 7.2fixed in 10.0.572018-11-01
CVE-2018-10587 [HIGH] CWE-78 CVE-2018-10587: NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions befo NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary code, resulting in remote code execution.
nvd
CVE-2017-16607P3HIGHCVSS 7.5fixed in 7.2.7662018-01-23
CVE-2017-16607 [HIGH] CWE-200 CVE-2017-16607: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within heapdumps.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download h
nvd
CVE-2017-16599P3MEDIUMCVSS 6.5v7.2.7302018-01-23
CVE-2017-16599 [MEDIUM] CWE-22 CVE-2017-16599: This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.templates.m
nvd
CVE-2017-16592P3MEDIUMCVSS 6.5v7.2.7302018-01-23
CVE-2017-16592 [MEDIUM] CWE-22 CVE-2017-16592: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the common.download_jsp servlet, wh
nvd
CVE-2017-16594P3MEDIUMCVSS 6.5v7.2.7302018-01-23
CVE-2017-16594 [MEDIUM] CWE-434 CVE-2017-16594: This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.db.save_005fimage_
nvd
CVE-2017-16605P3MEDIUMCVSS 6.5v7.2.7302018-01-23
CVE-2017-16605 [MEDIUM] CWE-22 CVE-2017-16605: This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.db.save_005fattr
nvd
CVE-2017-16604P3MEDIUMCVSS 6.5v7.2.7302018-01-23
CVE-2017-16604 [MEDIUM] CWE-22 CVE-2017-16604: This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.cnnic.asset.devi
nvd
CVE-2017-16593P3MEDIUMCVSS 6.5v7.2.7302018-01-23
CVE-2017-16593 [MEDIUM] CWE-22 CVE-2017-16593: This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.restore.del_005fdo_
nvd
CVE-2017-16595P3MEDIUMCVSS 6.5v7.2.7302018-01-23
CVE-2017-16595 [MEDIUM] CWE-22 CVE-2017-16595: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.ex
nvd
Netgain-Systems Enterprise Manager vulnerabilities | cvebase