VYPR
Vendor

Skybox

Products
5
CVEs
11
Across products
12
Status
Private

Products

5

Recent CVEs

11
  • CVE-2015-9249CriJan 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element.

  • CVE-2015-9246CriJan 12, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archive containing a JSP file. The WAR file is sent to /skyboxview-softwareupdate/services/CollectorSoftwareUpdate and the JSP file is reached at…

  • CVE-2017-14773HigOct 3, 2017
    risk 0.51cvss 7.8epss 0.00

    Skybox Manager Client Application prior to 8.5.501 is prone to an elevation of privileges vulnerability during authentication of a valid user in a debugger-pause state. The vulnerability can only be exploited by a local authenticated attacker.

  • CVE-2015-9250HigJan 12, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.

  • CVE-2017-14771MedOct 3, 2017
    risk 0.36cvss 5.5epss 0.00

    Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can…

  • CVE-2017-14770MedOct 3, 2017
    risk 0.36cvss 5.5epss 0.00

    Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated attacker can access the password hashes in a debugger-pause state during the authentication process.

  • CVE-2024-54853MedFeb 5, 2025
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser.

  • CVE-2015-9248MedJan 12, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the title, Comments, or Description field to /skyboxview/webskybox/tickets in Change Manager.

  • CVE-2015-9247MedJan 12, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body element, or in the status parameter to login.html.

  • CVE-2017-14772LowOct 3, 2017
    risk 0.21cvss 3.3epss 0.00

    Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing error messages upon valid and invalid account login attempts.

  • CVE-2014-2084May 17, 2014
    risk 0.03cvss epss 0.04

    Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote attackers to obtain sensitive information via a request to (1) scripts/commands/getSystemInformation…