{"id":630,"date":"2021-03-10T18:51:38","date_gmt":"2021-03-10T18:51:38","guid":{"rendered":"https:\/\/www.attackdebris.com\/?page_id=630"},"modified":"2023-08-03T15:36:45","modified_gmt":"2023-08-03T14:36:45","slug":"vulnerabilities-cves","status":"publish","type":"page","link":"https:\/\/www.attackdebris.com\/?page_id=630","title":{"rendered":"Vulnerabilities \/ CVEs"},"content":{"rendered":"\n<p>This page provides details of some of the vulnerabilites I&#8217;ve identified and reported to vendors down the years. <\/p>\n\n\n\n<p><strong>CVE-2021-20477<\/strong><br>IBM Planning Analytics Local &#8211; Cross-Site Scripting (XSS) Vulnerability<br> IBM Advisory: <a rel=\"noreferrer noopener\" href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6462331\" target=\"_blank\">https:\/\/www.ibm.com\/support\/pages\/node\/6462331<\/a><br>NIST CVE Record: <a rel=\"noreferrer noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-20477\" target=\"_blank\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-20477<\/a><\/p>\n\n\n\n<p><strong>June 2020<\/strong> <br>Parallels RAS Username Enumeration Flaw<br>Parallels RAS Release Notes: <a rel=\"noreferrer noopener\" href=\"https:\/\/kb.parallels.com\/en\/124713\" target=\"_blank\">https:\/\/kb.parallels<\/a><a href=\"https:\/\/kb.parallels.com\/en\/124713\">.com\/en\/124713<\/a><br>Blog Post: <a rel=\"noreferrer noopener\" href=\"https:\/\/www.attackdebris.com\/?p=602\" target=\"_blank\">https:\/\/www.attackdebris.com\/?p=602<\/a><\/p>\n\n\n\n<p><strong>CVE-2019-17360<\/strong><br>A Denial of Service (DoS) Vulnerability in Hitachi Command Suite and Hitachi Infrastructure Analytics Advisor<br>Hitachi Advisory: <a href=\"https:\/\/www.hitachi.co.jp\/Prod\/comp\/soft1\/global\/security\/info\/vuls\/hitachi-sec-2019-125\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.hitachi.co.jp\/Prod\/comp\/soft1\/global\/security\/info\/vuls\/hitachi-sec-2019-125\/<\/a><br>NIST CVE Record: <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-17360\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-17360<\/a><\/p>\n\n\n\n<p><strong>CVE-2018-21026<\/strong><br>Information Disclosure Vulnerability in Hitachi Command Suite<br>Hitachi Advisory: <a href=\"https:\/\/www.hitachi.co.jp\/Prod\/comp\/soft1\/global\/security\/info\/vuls\/hitachi-sec-2019-124\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.hitachi.co.jp\/Prod\/comp\/soft1\/global\/security\/info\/vuls\/hitachi-sec-2019-124\/<\/a><br>NIST CVE Record: <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-21026\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-21026<\/a><\/p>\n\n\n\n<p><strong>CVE-2017-6225<\/strong><br>Brocade Fabric OS Cross-Site Scripting (XSS) Vulnerability<br>Broadcom Advisory: <a rel=\"noreferrer noopener\" href=\"https:\/\/www.broadcom.com\/support\/fibre-channel-networking\/security-advisories\/brocade-security-advisory-2018-525\" target=\"_blank\">https:\/\/www.broadcom.com\/support\/fibre-channel-networking\/security-advisories\/brocade-security-advisory-2018-525<\/a><br>NIST CVE Record: <a rel=\"noreferrer noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-6225\" target=\"_blank\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-6225<\/a><\/p>\n\n\n\n<p><strong>CVE-2015-1429<\/strong><br>Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation<br>Cybelesoft Advisory: <a rel=\"noreferrer noopener\" href=\"https:\/\/www.cybelesoft.com\/blog\/cybele-software-inc-security-bulletin-2\/\" target=\"_blank\">https:\/\/www.cybelesoft.com\/blog\/cybele-software-inc-security-bulletin-2\/<\/a><br>NIST CVE Record: <a rel=\"noreferrer noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-1429\" target=\"_blank\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-1429<\/a><\/p>\n\n\n\n<p class=\"has-text-color\" style=\"color:#0071a1\"><br><br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This page provides details of some of the vulnerabilites I&#8217;ve identified and reported to vendors down the years. CVE-2021-20477IBM Planning Analytics Local &#8211; Cross-Site Scripting (XSS) Vulnerability IBM Advisory: https:\/\/www.ibm.com\/support\/pages\/node\/6462331NIST CVE Record: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-20477 June 2020 Parallels RAS Username Enumeration FlawParallels RAS Release Notes: https:\/\/kb.parallels.com\/en\/124713Blog Post: https:\/\/www.attackdebris.com\/?p=602 CVE-2019-17360A Denial of Service (DoS) Vulnerability in Hitachi Command &hellip; <\/p>\n<p><a class=\"more-link btn\" href=\"https:\/\/www.attackdebris.com\/?page_id=630\">Continue reading<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"jetpack_post_was_ever_published":false,"footnotes":""},"class_list":["post-630","page","type-page","status-publish","hentry","nodate","item-wrap"],"jetpack_shortlink":"https:\/\/wp.me\/P3MDvd-aa","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=\/wp\/v2\/pages\/630","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=630"}],"version-history":[{"count":7,"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=\/wp\/v2\/pages\/630\/revisions"}],"predecessor-version":[{"id":678,"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=\/wp\/v2\/pages\/630\/revisions\/678"}],"wp:attachment":[{"href":"https:\/\/www.attackdebris.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}