cbcvebase.

Netgain Systems Enterprise Manager vulnerabilities

23 known vulnerabilities affecting netgain_systems/netgain_systems_enterprise_manager.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH7MEDIUM11

Vulnerabilities

Page 1 of 2
CVE-2017-16608P1CRITICALCVSS 9.8Exploitedvv7.2.586 build 8772018-01-23
CVE-2017-16608 [CRITICAL] CWE-78 CVE-2017-16608: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call
nvd
CVE-2017-16602P1HIGHCVSS 8.8Exploitedv7.2.730 build 10342018-01-23
CVE-2017-16602 [HIGH] CWE-78 CVE-2017-16602: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.tools.exec_jsp servle
nvd
CVE-2017-16597P2CRITICALCVSS 9.8v7.2.730 build 10342018-01-23
CVE-2017-16597 [CRITICAL] CWE-22 CVE-2017-16597: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of WRQ requests. When parsing the Filename field, the process does not properly validat
nvd
CVE-2017-16603P2HIGHCVSS 8.8v7.2.730 build 10342018-01-23
CVE-2017-16603 [HIGH] CWE-22 CVE-2017-16603: This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.se
nvd
CVE-2017-16610P2CRITICALCVSS 9.8vv7.2.586 build 8772018-01-23
CVE-2017-16610 [CRITICAL] CWE-22 CVE-2017-16610: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operat
nvd
CVE-2017-17407P2CRITICALCVSS 9.8vv7.2.699 build 10012018-01-23
CVE-2017-17407 [CRITICAL] CWE-78 CVE-2017-17407: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the content parameter provided to the script_test.jsp endpoint. A crafted content req
nvd
CVE-2017-17406P2CRITICALCVSS 9.8vv7.2.586 build 8772018-01-23
CVE-2017-17406 [CRITICAL] CWE-502 CVE-2017-17406: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within an exposed RMI registry, which listens on TCP ports 1800 and 1850 by default. The issue results from the lack of proper validati
nvd
CVE-2017-16598P2HIGHCVSS 8.8v7.2.730 build 10342018-01-23
CVE-2017-16598 [HIGH] CWE-22 CVE-2017-16598: This vulnerability allows remote attackers to execute code by overwriting arbitrary files on vulnera This vulnerability allows remote attackers to execute code by overwriting arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp
nvd
CVE-2017-16606P2HIGHCVSS 8.8v7.2.730 build 10342018-01-23
CVE-2017-16606 [HIGH] CWE-22 CVE-2017-16606: This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp._3
nvd
CVE-2017-16590P3HIGHCVSS 8.8v7.2.699 build 10012018-01-23
CVE-2017-16590 [HIGH] CWE-289 CVE-2017-16590: This vulnerability allows remote attackers to bypass authentication on vulnerable installations of N This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1001. User interaction is required to exploit this vulnerability. The specific flaw exists within the MainFilter servlet. The issue results from the lack of proper string matching inside the doFilter metho
nvd
CVE-2017-16609P3HIGHCVSS 7.5vv7.2.586 build 8772018-01-23
CVE-2017-16609 [HIGH] CWE-39 CVE-2017-16609: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a f
nvd
CVE-2017-16607P3HIGHCVSS 7.5vv7.2.586 build 8772018-01-23
CVE-2017-16607 [HIGH] CWE-200 CVE-2017-16607: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within heapdumps.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download h
nvd
CVE-2017-16599P3MEDIUMCVSS 6.5v7.2.730 build 10342018-01-23
CVE-2017-16599 [MEDIUM] CWE-22 CVE-2017-16599: This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.templates.m
nvd
CVE-2017-16592P3MEDIUMCVSS 6.5v7.2.730 build 10342018-01-23
CVE-2017-16592 [MEDIUM] CWE-22 CVE-2017-16592: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the common.download_jsp servlet, wh
nvd
CVE-2017-16594P3MEDIUMCVSS 6.5v7.2.730 build 10342018-01-23
CVE-2017-16594 [MEDIUM] CWE-434 CVE-2017-16594: This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.db.save_005fimage_
nvd
CVE-2017-16605P3MEDIUMCVSS 6.5v7.2.730 build 10342018-01-23
CVE-2017-16605 [MEDIUM] CWE-22 CVE-2017-16605: This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.db.save_005fattr
nvd
CVE-2017-16604P3MEDIUMCVSS 6.5v7.2.730 build 10342018-01-23
CVE-2017-16604 [MEDIUM] CWE-22 CVE-2017-16604: This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.cnnic.asset.devi
nvd
CVE-2017-16593P3MEDIUMCVSS 6.5v7.2.730 build 10342018-01-23
CVE-2017-16593 [MEDIUM] CWE-22 CVE-2017-16593: This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.restore.del_005fdo_
nvd
CVE-2017-16595P3MEDIUMCVSS 6.5v7.2.730 build 10342018-01-23
CVE-2017-16595 [MEDIUM] CWE-22 CVE-2017-16595: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.ex
nvd
CVE-2017-16591P3MEDIUMCVSS 6.5v7.2.699 build 10012018-01-23
CVE-2017-16591 [MEDIUM] CWE-22 CVE-2017-16591: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1001. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.restore.do
nvd
Netgain Systems Enterprise Manager vulnerabilities | cvebase