Known vulnerabilities in CBAS Web
Vendor:
Computrols
Software:
CBAS Web
Software CPE:
cpe:2.3:a:computrols:cbas_web:*:*:*:*:*:*:*:*
Website:
https://www.computrols.com/
Total vulnerabilities:
9
Public exploits:
6
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU18655 - Exposure of sensitive information to an unauthorized actor CVE-2019-10855 |
CWE-200 | Medium | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052327 |
||
| #VU18653 - Improper Authentication CVE-2019-10853 |
CWE-287 | High | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052326 |
||
| #VU18651 - Use of Hard-coded Credentials CVE-2019-10851 |
CWE-798 | Medium | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052325 |
||
| #VU18650 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2019-10852 |
CWE-89 | Medium | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052324 |
||
| #VU18649 - Exposure of sensitive information to an unauthorized actor CVE-2019-10849 |
CWE-200 | Medium | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052323 |
||
| #VU18648 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2019-10854 |
CWE-78 | High | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052322 |
||
| #VU18647 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-10846 |
CWE-79 | Medium | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052321 |
||
| #VU18646 - Exposure of sensitive information to an unauthorized actor CVE-2019-10848 |
CWE-200 | Medium | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 31.05.2019 |
SB2019052413 |
||
| #VU18644 - Cross-Site Request Forgery (CSRF) CVE-2019-10847 |
CWE-352 | Medium | 3.15.1, 4.8.2, 6.9.2, 7.2.1 Beta, 8.0.7, 14.0.1, 15.0.1, 18.0.1, 19.0.1 | 30.05.2019 |
SB2019052412 |