VYPR

Ootbi

by Object First

CVEs (3)

  • CVE-2022-44796CriNov 7, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows getting access to the Web UI without knowing credentials. For signing, the JWT token uses a secret key that is generated through a function that doesn't produce…

  • CVE-2022-44794HigNov 7, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary…

  • CVE-2022-44795MedNov 7, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates the URL for the support bundle uses an insecure RNG. That can lead to prediction of the generated…