WAON
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-4832 | Med | 0.38 | 5.9 | 0.01 | Apr 21, 2017 | WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates. | ||
| CVE-2019-11280 | 0.00 | — | 0.01 | Sep 20, 2019 | Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote… | |||
| CVE-2019-3777 | 0.00 | — | 0.02 | Mar 7, 2019 | Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker that could hijack the Cloud Controller's… | |||
| CVE-2018-1278 | 0.00 | — | 0.01 | May 11, 2018 | Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be… |
- risk 0.38cvss 5.9epss 0.01
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.
- CVE-2019-11280Sep 20, 2019risk 0.00cvss —epss 0.01
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote…
- CVE-2019-3777Mar 7, 2019risk 0.00cvss —epss 0.02
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker that could hijack the Cloud Controller's…
- CVE-2018-1278May 11, 2018risk 0.00cvss —epss 0.01
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be…