CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,428)
page 250 of 672| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-3556 | Hig | 0.47 | 7.3 | 0.00 | Nov 6, 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of… | ||
| CVE-2020-1677 | Hig | 0.47 | 7.2 | 0.00 | Oct 16, 2020 | When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security… | ||
| CVE-2020-1676 | Hig | 0.47 | 7.2 | 0.01 | Oct 16, 2020 | When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security controls. This issue… | ||
| CVE-2020-24593 | Hig | 0.47 | 7.2 | 0.01 | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation. | ||
| CVE-2019-7178 | Hig | 0.47 | 7.2 | 0.02 | Sep 25, 2020 | Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup. | ||
| CVE-2019-15957 | Hig | 0.47 | 7.2 | 0.03 | Sep 23, 2020 | A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system. When processed, the commands… | ||
| CVE-2020-3454 | Hig | 0.47 | 7.2 | 0.03 | Aug 27, 2020 | A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient input… | ||
| CVE-2020-3218 | Hig | 0.47 | 7.2 | 0.05 | Jun 3, 2020 | A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell. The vulnerability is due to improper validation of user-supplied… | ||
| CVE-2020-6248 | Hig | 0.47 | 7.2 | 0.02 | May 12, 2020 | SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection. | ||
| CVE-2020-3309 | Hig | 0.47 | 7.2 | 0.02 | May 6, 2020 | A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation. An attacker could… | ||
| CVE-2019-2216 | Hig | 0.47 | 7.3 | 0.00 | Mar 15, 2020 | In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privilege because the user is not notified of an overlaying app, with User execution privileges needed. User interaction is needed for… | ||
| CVE-2020-6202 | Hig | 0.47 | 7.2 | 0.01 | Mar 10, 2020 | SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation. | ||
| CVE-2020-6192 | Hig | 0.47 | 7.2 | 0.02 | Feb 12, 2020 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. | ||
| CVE-2020-6191 | Hig | 0.47 | 7.2 | 0.02 | Feb 12, 2020 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation. | ||
| CVE-2019-16005 | Hig | 0.47 | 7.2 | 0.04 | Jan 26, 2020 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management… | ||
| CVE-2011-3611 | Hig | 0.47 | 7.2 | 0.03 | Jan 22, 2020 | A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12. | ||
| CVE-2019-19902 | Hig | 0.47 | 7.2 | 0.01 | Dec 19, 2019 | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing… | ||
| CVE-2013-4245 | Hig | 0.47 | 7.3 | 0.01 | Dec 11, 2019 | Orca has arbitrary code execution due to insecure Python module load | ||
| CVE-2019-1944 | Hig | 0.47 | 7.3 | 0.00 | Aug 7, 2019 | Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information… | ||
| CVE-2018-20895 | Hig | 0.47 | 7.2 | 0.01 | Aug 1, 2019 | In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). |
- risk 0.47cvss 7.3epss 0.00
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of…
- risk 0.47cvss 7.2epss 0.00
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security…
- risk 0.47cvss 7.2epss 0.01
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security controls. This issue…
- risk 0.47cvss 7.2epss 0.01
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.
- risk 0.47cvss 7.2epss 0.02
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
- risk 0.47cvss 7.2epss 0.03
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system. When processed, the commands…
- risk 0.47cvss 7.2epss 0.03
A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient input…
- risk 0.47cvss 7.2epss 0.05
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell. The vulnerability is due to improper validation of user-supplied…
- risk 0.47cvss 7.2epss 0.02
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.
- risk 0.47cvss 7.2epss 0.02
A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation. An attacker could…
- risk 0.47cvss 7.3epss 0.00
In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privilege because the user is not notified of an overlaying app, with User execution privileges needed. User interaction is needed for…
- risk 0.47cvss 7.2epss 0.01
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.
- risk 0.47cvss 7.2epss 0.02
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.
- risk 0.47cvss 7.2epss 0.02
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.
- risk 0.47cvss 7.2epss 0.04
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management…
- risk 0.47cvss 7.2epss 0.03
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing…
- risk 0.47cvss 7.3epss 0.01
Orca has arbitrary code execution due to insecure Python module load
- risk 0.47cvss 7.3epss 0.00
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information…
- risk 0.47cvss 7.2epss 0.01
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).