Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sapphireims CRITICAL 9.8
CVE-2020-25563

In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTask…

No fix yet
Fix from $2,300 2021-08-11
Sapphireims CRITICAL 9.8
CVE-2020-25565

In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once…

No fix yet
Fix from $2,300 2021-08-11
Sapphireims CRITICAL 9.8
CVE-2020-25566

In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not requ…

No fix yet
Fix from $2,300 2021-08-11
Sapphireims HIGH 8.8
CVE-2020-25564

In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing Remote…

No fix yet
Fix from $1,950 2021-08-11
Sapphireims HIGH 7.8
CVE-2020-25561

SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the cl…

No fix yet
Fix from $1,950 2021-08-11
Sapphireims MEDIUM 6.5
CVE-2020-25562

In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms lik…

No fix yet
Fix from $1,600 2021-08-11
Sapphireims CRITICAL 9.8
CVE-2020-25560

In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once…

No fix yet
Fix from $2,300 2021-08-11
Sapphireims HIGH 8.8
CVE-2017-16630

In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Dir…

Mitigation only
Fix from $1,950 2021-08-11
Sapphireims HIGH 7.5
CVE-2017-16629

In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives out for each type of user on …

Mitigation only
Fix from $1,950 2021-08-11
Sapphireims HIGH 7.5
CVE-2017-16632

In SapphireIMS 4097_1, the password in the database is stored in Base64 format.

Mitigation only
Fix from $1,950 2021-08-11
Sapphireims MEDIUM 6.5
CVE-2017-16631

In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Direct Object Reference (IDOR) …

Mitigation only
Fix from $1,600 2021-08-11