Skip to main content

Vendor archive

fujitsu CVEs

Beta · best-effort

76 CVEs tagged to vendor fujitsu12 Critical, 22 High, 37 Medium, 5 Low, 0 Unrated.

CVE-2023-4096

Published Sep 19, 2023

Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4095

Published Sep 19, 2023

User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the applica…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4094

Published Sep 19, 2023

ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a deni…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4093

Published Sep 19, 2023

Reflected and persistent XSS vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to inject malicious JavaScript…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4092

Published Sep 19, 2023

SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39903

Published Aug 7, 2023

An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in this specific case at /var/log/fujitsu/ServerViewSuite/ism/Fir…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39379

Published Aug 4, 2023

Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27089

Published Apr 11, 2022

In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20722

Published May 24, 2021

Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-17457

Published Mar 17, 2021

Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The pay…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8177

Published Dec 14, 2020

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS 7.8 · High
Showing 1-25 of 76 CVEsPage 1 of 4