4.3
CVE-2024-9143 - Low-level invalid GF(2^m) parameters lead to OOB memory access
Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. Impact summary: Out of bound memory writes can lead to an application crash or even a possibility of a remote code execution, hoโฆ
8.8
CVE-2024-38814 -
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager.ย Updates are availabโฆ
1.8
CVE-2024-4692 - Multiple missing permission checks
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Applicaโฆ
5.1
CVE-2024-4690 - Insecure usage for DocumentBuilderFactory and TransformerFactory in OpenText Application Automationโฆ
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
1.8
CVE-2024-4211 - Multiple missing permission checks
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Toโฆ
5.9
CVE-2024-4189 - Multiple XXE sinks in Run LoadRunner script step in OpenText Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
5.9
CVE-2024-4184 - Multiple XXE sinks in ALM archive post-build step in OpenText Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
0.0
CVE-2024-10042 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.3
CVE-2023-32266 - Code injection vulnerability found in OpenText Application Lifecycle Management (ALM),Quality Centeโฆ
Untrusted Search Path vulnerability in OpenTextโข Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation. ย This issue affects Application Lifecycle Management (ALM),Quality Cenโฆ
5.5
CVE-2024-45071 - IBM WebSphere Application Server cross-site scripting
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.