VYPR

Cloud

by Jedox

CVEs (4)

  • CVE-2022-47875HigMay 2, 2023
    risk 0.61cvss 8.8epss 0.10

    A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

  • CVE-2022-47879HigMay 12, 2023
    risk 0.52cvss 7.5epss 0.06

    A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version…

  • CVE-2022-47874MedMay 2, 2023
    risk 0.47cvss 6.5epss 0.21

    Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.

  • CVE-2022-47880MedMay 12, 2023
    risk 0.38cvss 5.3epss 0.03

    An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.