Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Mobile Application Platform
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-1723 1 Redhat 1 Mobile Application Platform 2021-02-04 4.3 MEDIUM 4.3 MEDIUM
The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.
CVE-2017-7553 1 Redhat 1 Mobile Application Platform 2017-12-31 6.5 MEDIUM 6.3 MEDIUM
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
CVE-2017-7554 1 Redhat 1 Mobile Application Platform 2017-12-31 4.3 MEDIUM 6.1 MEDIUM
It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio.