knowage-suite knowage CVE Vulnerabilities (4)

CVEs: 4 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting knowage-suite knowage (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2019-14278 In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page. [email protected] 5.3 0.43% 2019-09-05 2024-11-21
CVE-2019-13349 In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes. [email protected] 4.9 1.04% 2019-09-05 2024-11-21
CVE-2018-12354 Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analyticalDrivers/ POST request. [email protected] 8.8 0.09% 2018-06-13 2024-11-21
CVE-2018-12353 Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue. [email protected] 6.1 0.24% 2018-06-13 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence