Vulnerabilities (CVE)

Filtered by vendor Imperva Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-5403 1 Imperva 1 Securesphere 2019-10-09 6.8 MEDIUM 8.1 HIGH
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.
CVE-2018-5412 1 Imperva 1 Securesphere 2019-10-09 7.2 HIGH 7.8 HIGH
Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.
CVE-2018-5413 1 Imperva 1 Securesphere 2019-10-09 6.5 MEDIUM 8.8 HIGH
Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.
CVE-2018-16660 1 Imperva 1 Securesphere 2019-04-29 9.0 HIGH 8.8 HIGH
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.