Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
knowage vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2019-14278
In Knowage up to and including 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
Knowage-suite Knowage
356
VMScore
CVE-2019-13349
In Knowage up to and including 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
Knowage-suite Knowage
605
VMScore
CVE-2018-12354
Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analyticalDrivers/ POST request.
Knowage-suite Knowage 6.1.1
383
VMScore
CVE-2018-12353
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
Knowage-suite Knowage 6.1.1
NA
CVE-2023-35154
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allowing them access to the application as a n...
Eng Knowage
NA
CVE-2023-38702
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/restful-services/dossier/importTemplateFile` allows authenticated users to upload `template file` on the server, but does not need ...
Eng Knowage
356
VMScore
CVE-2019-13348
In Knowage up to and including 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
Eng Knowage
NA
CVE-2023-36819
Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/restful-services/dossier/importTemplateFile_` allows authenticated users to download template hosted on the server. However, starting...
Eng Knowage
383
VMScore
CVE-2021-30058
Knowage Suite prior to 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter.
Eng Knowage
445
VMScore
CVE-2019-13188
In Knowage up to and including 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
Eng Knowage
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
brute force
CVE-2024-24908
open redirect
CVE-2024-31497
CVE-2023-45866
CVE-2024-4135
CVE-2024-25523
cache poisoning
CVE-2024-4649
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »