MidnightBSD

Advisories for xceedium

CVE-2015-4664 HIGH

An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
xceedium xsuite 2.3.0
broadcom privileged_access_manager *
xceedium xsuite 2.4.3.0
CVE-2015-4665 MEDIUM

Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
xceedium xsuite 2.3.0
xceedium xsuite 2.4.3.0
CVE-2015-4666 MEDIUM

Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
xceedium xsuite 2.3.0
xceedium xsuite 2.4.3.0
CVE-2015-4667 HIGH

Multiple hardcoded credentials in Xsuite 2.x.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
xceedium xsuite 2.3.0
xceedium xsuite 2.4.3.0
CVE-2015-4668 MEDIUM

Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
xceedium xsuite 2.3.0
xceedium xsuite 2.4.3.0
CVE-2015-4669 HIGH

The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
xceedium xsuite 2.3.0
xceedium xsuite 2.4.3.0