bssys CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

bssys vulnerability overview

Aggregates CVE and security vulnerability intelligence across all bssys-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk sql injection, with potential vendor impact session compromise and vendor impact data exposure across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2014-4198 A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function. [email protected] 9.1 0.28% 2020-02-13 2024-11-21
CVE-2014-4196 Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attackers to inject arbitrary web script or HTML via the colorstyle parameter. [email protected] 6.1 0.19% 2020-01-03 2024-11-21
CVE-2014-10398 Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) DICTIONARY, (2) FILTERIDENT, (3) FROMSCHEME, (4) FromPoint, or (5) FName_0 parameter and a valid sid parameter value. [email protected] 6.1 0.31% 2020-01-03 2024-11-21
CVE-2014-4197 Multiple SQL injection vulnerabilities in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allow remote attackers to execute arbitrary SQL commands via the (1) CARDS or (2) XACTION parameter. [email protected] 7.5 0.32% 2014-08-22 2026-05-06
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence