Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-45876 | 1 Visam | 1 Vbase | 2024-11-21 | N/A | 5.5 MEDIUM |
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |||||
CVE-2022-3217 | 1 Visam | 1 Vbase | 2024-11-21 | N/A | 7.5 HIGH |
When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the ability to capture a login session can obtain the login credentials. |