VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago
Reset
More filters (2)
Columns
Published from 2010-11-01Published to 2010-11-30
Overview 8 matches, all in RASP scope · 1 protected · 0 KEV · 2 public PoC · 0 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
8matches, all in RASP scope 1protected12.5% 0KEV0.0% 2public PoC25.0% 0CISA SSVC0.0% 1EPSS ≥ 0.512.5% 0disputed0.0%
Critical 0 0.0% High 0 0.0% Medium 8 100.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 1 12.5% Rule in development 0 0.0% Mitigation candidate 1 12.5% No exploit published 1 12.5% No fix identified 5 62.5% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 1 12.5% not blocked 7 87.5% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 2 25.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 6 75.0%
split by peak 8 / month
Unknown: 0None: 0Low: 0Medium: 8High: 0Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 5No exploit published: 1Mitigation candidate: 1Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 7blocked by ARMR today: 1 No public exploit: 6Forecast only: 0Proof of concept only: 0Working exploit published: 2Exploited in the wild: 0 November 2010: 8 CVEs
Nov 10
8 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2010-4312 Medium 2010-11-26 No exploit published No public exploit The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
CVE-2010-4172 Medium 2010-11-26 Mitigation candidate Working exploit published Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
CVE-2010-4220 Medium 2010-11-09 No fix identified No public exploit Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
CVE-2010-0786 Medium 2010-11-09 No fix identified No public exploit The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.
CVE-2010-0785 Medium 2010-11-09 No fix identified No public exploit Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2010-0784 Medium 2010-11-09 No fix identified No public exploit Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-0783 Medium 2010-11-09 No fix identified No public exploit Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-3863 Medium 2010-11-05 Protected by RASP Working exploit published Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.