VYPR

InfraBox

by SAP

CVEs (2)

  • CVE-2021-33668HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.

  • CVE-2021-33706MedAug 10, 2021
    risk 0.28cvss 4.3epss 0.01

    Due to improper input validation in InfraBox, logs can be modified by an authenticated user.