Absolute Software
Products
1- 10 CVEs
Recent CVEs
10| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-37352 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that allows attackers with system administrator permissions to interfere with other system administrators’ use of the management UI when the second administrator… | |||
| CVE-2024-37351 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the second administrator later… | |||
| CVE-2024-37350 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. Attackers can interfere with a system administrator’s use of the policy management UI when the attacker convinces the victim administrator to follow a… | |||
| CVE-2024-37349 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the victim administrator edits the… | |||
| CVE-2024-37348 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the management UI when the second administrator later… | |||
| CVE-2024-37347 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can pass a limited length script to be run by another administrator. The scope is… | |||
| CVE-2024-37346 | 0.00 | — | 0.00 | Jun 20, 2024 | There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid… | |||
| CVE-2024-37345 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is… | |||
| CVE-2024-37344 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the policy management UI when the administrators… | |||
| CVE-2024-37343 | 0.00 | — | 0.00 | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored… |
- CVE-2024-37352Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that allows attackers with system administrator permissions to interfere with other system administrators’ use of the management UI when the second administrator…
- CVE-2024-37351Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the second administrator later…
- CVE-2024-37350Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. Attackers can interfere with a system administrator’s use of the policy management UI when the attacker convinces the victim administrator to follow a…
- CVE-2024-37349Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the victim administrator edits the…
- CVE-2024-37348Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the management UI when the second administrator later…
- CVE-2024-37347Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can pass a limited length script to be run by another administrator. The scope is…
- CVE-2024-37346Jun 20, 2024risk 0.00cvss —epss 0.00
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid…
- CVE-2024-37345Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is…
- CVE-2024-37344Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the policy management UI when the administrators…
- CVE-2024-37343Jun 20, 2024risk 0.00cvss —epss 0.00
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored…