InfraBox
by SAP
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33668 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2021 | Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application. | ||
| CVE-2021-33706 | Med | 0.28 | 4.3 | 0.01 | Aug 10, 2021 | Due to improper input validation in InfraBox, logs can be modified by an authenticated user. |
- risk 0.49cvss 7.5epss 0.01
Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.
- risk 0.28cvss 4.3epss 0.01
Due to improper input validation in InfraBox, logs can be modified by an authenticated user.