VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 51 minutes ago
Reset
More filters (3)
Columns
Protection: fullPublished from 2020-09-01Published to 2020-09-30
Overview 15 matches, all in RASP scope, all protected · 0 KEV · 2 public PoC · 0 CISA SSVC · 2 EPSS ≥ 0.5 · 0 disputed
15matches, all in RASP scope, all protected 0KEV0.0% 2public PoC13.3% 0CISA SSVC0.0% 2EPSS ≥ 0.513.3% 0disputed0.0%
Critical 2 13.3% High 8 53.3% Medium 5 33.3% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 15 100.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 15 100.0% not blocked 0 0.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 1 6.7% Proof of concept only 0 0.0% Forecast only 1 6.7% No public exploit 13 86.7%
split by peak 15 / month
Unknown: 0None: 0Low: 0Medium: 5High: 8Critical: 2 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 15 unrecorded: 0not established: 0not blocked: 0blocked by ARMR today: 15 No public exploit: 13Forecast only: 1Proof of concept only: 0Working exploit published: 1Exploited in the wild: 0 September 2020: 15 CVEs
Sep 20
15 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2020-2284 High 2020-09-23 Protected by RASP No public exploit Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-4643 High 2020-09-21 Protected by RASP No public exploit IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
CVE-2020-24750 High 2020-09-17 Protected by RASP No public exploit FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
CVE-2020-2278 Medium 2020-09-16 Protected by RASP No public exploit Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to replace any other '.xml' file on the Jenkins controller with a job config.xml file's content.
CVE-2020-2277 Medium 2020-09-16 Protected by RASP No public exploit Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jenkins controller.
CVE-2020-2276 High 2020-09-16 Protected by RASP No public exploit Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure permission to execute an arbitrary system command on the Jenkins controller as the OS user that the Jenkins process is running as.
CVE-2020-2275 Medium 2020-09-16 Protected by RASP No public exploit Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.
CVE-2020-2261 High 2020-09-16 Protected by RASP No public exploit Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller
CVE-2020-2254 Medium 2020-09-16 Protected by RASP No public exploit Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.
CVE-2020-11977 High 2020-09-15 Protected by RASP No public exploit In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.
CVE-2019-0230 Critical 2020-09-14 Protected by RASP Working exploit published Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
CVE-2020-24164 High 2020-09-11 Protected by RASP No public exploit A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.
CVE-2020-11998 Critical 2020-09-10 Protected by RASP Forecast only A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13
CVE-2020-2247 Medium 2020-09-01 Protected by RASP No public exploit Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2245 High 2020-09-01 Protected by RASP No public exploit Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.