apexsoftcell CVE 脆弱性と CVE 一覧(5)

製品(CPE): — CVE 件数: 5

apexsoftcell 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to apexsoftcell, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 15 / 5 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2024-47089 This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating the transaction token ID in the API request leading to unauthorized access and modification of transactions belonging to other users. [email protected] 8.7 0.22% 2024-09-19 2024-09-26
CVE-2024-47088 This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts. [email protected] 9.3 0.55% 2024-09-19 2024-09-26
CVE-2024-47087 This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. [email protected] 8.7 0.43% 2024-09-19 2024-09-26
CVE-2024-47086 This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts. [email protected] 8.7 0.47% 2024-09-19 2024-09-26
CVE-2024-47085 This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. [email protected] 8.7 0.43% 2024-09-19 2024-09-26
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence