monitoring software vulnerabilities
vulnerabilities.aspcode.net
Searching monitoring software vulnerabilities
HTTP server in Alchemy Eye and Alchemy Network
through
|
Network
|
Monitor
|
Alchemy
|
server
|
HTTP
|
19x
|
Eye
|
HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.
The default configuration of Oracle 9i Applicat
authentication
|
configuration
|
Application
|
Monitoring
|
anonymous
|
sensitive
|
including
|
services
|
without
|
Dynamic
|
default
|
Server
|
Oracle
|
access
|
allows
|
remote
|
users
|
102x
|
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
The design of the Internet Key Exchange (IKE) p
Exchange
|
Internet
|
design
|
Key
|
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.
Secure Computing Corporation Sidewinder G2 6.1.
Corporation
|
Sidewinder
|
Computing
|
Secure
|
Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter. NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.
Secure Computing Corporation Sidewinder G2 6.1.
Corporation
|
Sidewinder
|
Computing
|
Secure
|
Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.
Directory traversal vulnerability in ServersChe
vulnerability
|
ServersCheck
|
Monitoring
|
traversal
|
Directory
|
Software
|
Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.
core/database_api.php in Mantis 0.19.0a1 throug
core/database_apiphp
|
register_globals
|
bug#0005956
|
identified
|
monitoring
|
modifying
|
attackers
|
g_db_type
|
responses
|
databases
|
internal
|
variable
|
enabled
|
through
|
connect
|
0190a1
|
Mantis
|
allows
|
remote
|
100a3
|
speed
|
core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.
Unspecified vulnerability in the SSL certificat
functionality
|
vulnerability
|
Unspecified
|
certificate
|
Management
|
CiscoWorks
|
checking
|
Sensors
|
Center
|
Cisco
|
SSL
|
IDS
|
Unspecified vulnerability in the SSL certificate checking functionality in Cisco CiscoWorks Management Center for IDS Sensors (IDSMC) 2.0 and 2.1, and Monitoring Center for Security (Security Monitor or Secmon) 1.1 through 2.0 and 2.1, allows remote attackers to spoof a Cisco Intrusion Detection Sensor (IDS) or Intrusion Prevention System (IPS).
Cisco Security Monitoring, Analysis and Respons
Monitoring
|
Analysis
|
Response
|
Security
|
System
|
Cisco
|
Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.
Buffer overflow in Hawk Monitoring Agent (HMA)
Monitoring
|
overflow
|
Buffer
|
Agent
|
Hawk
|
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma.
Cisco Security Monitoring, Analysis and Respons
Monitoring
|
Analysis
|
Response
|
Security
|
System
|
Cisco
|
Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts and passwords, which allows attackers to obtain sensitive information.
jmx-console/HtmlAdaptor in the jmx-console in t
jmx-console/HtmlAdaptor
|
application
|
jmx-console
|
Monitoring
|
Security
|
Response
|
Analysis
|
shipped
|
System
|
server
|
Cisco
|
JBoss
|
web
|
jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute arbitrary Java code via an invokeOp action in the BSHDeployer jboss.scripts service name.
Multiple unspecified vulnerabilities in the Com
vulnerabilities
|
unspecified
|
Interface
|
Multiple
|
Command
|
Line
|
Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.
The Cisco Security Monitoring, Analysis and Res
Monitoring
|
Analysis
|
Response
|
Security
|
System
|
Cisco
|
The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.
Cross-site scripting (XSS) vulnerability in ser
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.
ircu 2.10.12.05 and earlier allows remote attac
ircu
|
ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) certain other arguments that represent groups of IP addresses, then monitoring CTCP ping replies.
Software vulnerabilities results 1 to 17 of 17
Page:
1