Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-7576

A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2), Opcenter Execution Core (V8.2). An authenticated user with the ability to create containers, packages or register defects could perform stored Cross-Site Scripting (XSS) attacks within the vulnerable software. The impact of this attack could result in the session cookies of legitimate users being stolen. Should the attacker gain access to these cookies, they could then hijack the session and perform arbitrary actions in the name of the victim.

CVE
#xss#vulnerability#git#pdf#auth

%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 630.026 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 245.88 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 99.116 null] >> endobj 6 0 obj << /D [7 0 R /XYZ 85.039 586.151 null] >> endobj 8 0 obj << /D [7 0 R /XYZ 70.866 373.907 null] >> endobj 9 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 10 0 R /Type /Page /Resources 11 0 R /Parent 12 0 R /Annots [13 0 R 14 0 R 15 0 R 16 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 13 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 445.075 446.757 457.981] >> endobj 14 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 384.766 446.757 397.672] >> endobj 15 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 324.457 446.757 337.364] >> endobj 16 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 264.149 446.757 277.055] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/cert/operational-guidelines-industrial-security) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [164.798 698.869 487.754 710.406] >> endobj 11 0 obj << /ProcSet [/PDF /Text] /Font << /F54 18 0 R /F51 19 0 R >> >> endobj 10 0 obj << /Filter /FlateDecode /Length 2526 >> stream x���r�F����� ���\YN9�-ڒ);�e�)�!@)��y� ! eO� l�߾7Hr��䧣/����4��UL%�D��(�hk3Iur1M>��eqS,�јi����z4�2-����������I�>�Xs���~��n&����޾�~������G" �’@f��drs��w�L��� ɸ5ɝ{�&�gRp��’�G���T�v`"{Z�����բ��#�3+�n Hڌ*t~

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda