VYPR

IMPACT

by Nokia

CVEs (9)

  • CVE-2019-17403HigNov 25, 2019
    risk 0.57cvss 8.8epss 0.03

    Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.

  • CVE-2021-35486HigMar 3, 2026
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor…

  • CVE-2021-35484HigMar 3, 2026
    risk 0.53cvss 8.2epss 0.00

    Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker…

  • CVE-2021-35485HigMar 3, 2026
    risk 0.52cvss 8.0epss 0.00

    The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application,…

  • CVE-2019-17405MedNov 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Nokia IMPACT < 18A: has Reflected self XSS

  • CVE-2019-17406MedNov 25, 2019
    risk 0.35cvss 5.3epss 0.01

    Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743

  • CVE-2019-17404MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Nokia IMPACT < 18A: allows full path disclosure

  • CVE-2021-35483MedMar 3, 2026
    risk 0.27cvss 4.1epss 0.00

    The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during…

  • CVE-2023-31044LowMar 3, 2026
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate…