Redhat Enterprise MRG 2.4

CPE Details

Redhat Enterprise MRG 2.4
2.4
2018-01-04
14h56 +00:00
2021-07-15
17h15 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:redhat:enterprise_mrg:2.4:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

enterprise_mrg

Version

2.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2013-4404 2013-12-23 21h00 +00:00 cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.
6.5
CVE-2013-4405 2013-12-23 21h00 +00:00 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests.
6.8
CVE-2013-4414 2013-12-23 21h00 +00:00 Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
4.3
CVE-2013-4461 2013-12-23 21h00 +00:00 SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
7.5
CVE-2013-4345 2013-10-10 08h00 +00:00 Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data.
5.8
CVE-2013-4284 2013-10-09 14h44 +00:00 Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.
5