Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
afaria vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2015-4161
SAP Afaria does not properly restrict access to unspecified functionality, which allows remote malicious users to obtain sensitive information, gain privileges, or have other unspecified impact via unknown vectors, SAP Security Note 2155690.
Sap Afaria -
NA
CVE-2015-2820
Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote malicious users to cause a denial of service (process termination) via a crafted request, aka SAP Security Note 2132584.
Sap Afaria 7.0.6001.5
NA
CVE-2015-4092
Buffer overflow in the XComms process in SAP Afaria 7.00.6620.2 SP5 allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, aka SAP Security Note 2153690.
Sap Afaria 7.0.6620.2
9.1
CVSSv3
CVE-2015-8753
SAP Afaria 7.0.6001.5 allows remote malicious users to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.
Sap Afaria 7.0.6001.5
NA
CVE-2015-2816
The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote malicious users to have unspecified impact via a crafted request, aka SAP Security Note 2134905.
Sap Afaria 7.0.6001.5
NA
CVE-2015-3449
The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService.exe file.
Sap Afaria 7.0.6398.0
NA
CVE-2015-6663
Cross-site scripting (XSS) vulnerability in the Client form in the Device Inspector page in SAP Afaria 7 allows remote malicious users to inject arbitrary web script or HTML via crafted client name data, aka SAP Security Note 2152669.
Sap Afaria 7.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
hardcoded
arbitrary code
CVE-2024-2404
CVE-2024-21111
CVE-2024-28627
CVE-2024-4073
information disclosure
CVE-2024-32780
CVE-2024-4040
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started