Vulnerabilities (CVE)

Filtered by vendor Gemalto Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-8283 1 Gemalto 1 Sentinel Ldk 2021-09-14 4.3 MEDIUM 6.5 MEDIUM
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
CVE-2019-9157 1 Gemalto 1 Ezio Ds3 Server 2021-07-21 2.7 LOW 5.7 MEDIUM
Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
CVE-2019-8282 1 Gemalto 1 Sentinel Ldk 2020-10-22 2.6 LOW 5.3 MEDIUM
Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack by malicious one.
CVE-2019-9158 1 Gemalto 1 Ezio Ds3 Server 2020-08-24 2.7 LOW 5.7 MEDIUM
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
CVE-2018-8900 1 Gemalto 1 Sentinel Ldk Rte 2018-06-14 4.3 MEDIUM 6.1 MEDIUM
The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability.