IMPACT
by Nokia
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17403 | Hig | 0.57 | 8.8 | 0.03 | Nov 25, 2019 | Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution. | ||
| CVE-2021-35486 | Hig | 0.53 | 8.1 | 0.00 | Mar 3, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor… | ||
| CVE-2021-35484 | Hig | 0.53 | 8.2 | 0.00 | Mar 3, 2026 | Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker… | ||
| CVE-2021-35485 | Hig | 0.52 | 8.0 | 0.00 | Mar 3, 2026 | The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application,… | ||
| CVE-2019-17405 | Med | 0.40 | 6.1 | 0.01 | Nov 25, 2019 | Nokia IMPACT < 18A: has Reflected self XSS | ||
| CVE-2019-17406 | Med | 0.35 | 5.3 | 0.01 | Nov 25, 2019 | Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743 | ||
| CVE-2019-17404 | Med | 0.28 | 4.3 | 0.01 | Nov 25, 2019 | Nokia IMPACT < 18A: allows full path disclosure | ||
| CVE-2021-35483 | Med | 0.27 | 4.1 | 0.00 | Mar 3, 2026 | The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during… | ||
| CVE-2023-31044 | Low | 0.13 | 2.0 | 0.00 | Mar 3, 2026 | An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate… |
- risk 0.57cvss 8.8epss 0.03
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
- risk 0.53cvss 8.1epss 0.00
A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor…
- risk 0.53cvss 8.2epss 0.00
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker…
- risk 0.52cvss 8.0epss 0.00
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application,…
- risk 0.40cvss 6.1epss 0.01
Nokia IMPACT < 18A: has Reflected self XSS
- risk 0.35cvss 5.3epss 0.01
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
- risk 0.28cvss 4.3epss 0.01
Nokia IMPACT < 18A: allows full path disclosure
- risk 0.27cvss 4.1epss 0.00
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during…
- risk 0.13cvss 2.0epss 0.00
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate…