Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Expresscluster_x
(Nec)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 19 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-09-10 | CVE-2020-17408 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker... | Expresscluster_x | 7.5 | ||
2021-11-03 | CVE-2021-20700 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 9.8 | ||
2021-11-03 | CVE-2021-20701 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 9.8 | ||
2021-11-03 | CVE-2021-20702 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 9.8 | ||
2021-11-03 | CVE-2021-20703 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 9.8 | ||
2021-11-03 | CVE-2021-20704 | Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 9.8 | ||
2021-11-03 | CVE-2021-20705 | Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 7.5 | ||
2021-11-03 | CVE-2021-20706 | Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 7.5 | ||
2021-11-03 | CVE-2021-20707 | Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network.. | Clusterpro_x, Clusterpro_x_singleserversafe, Expresscluster_x, Expresscluster_x_singleserversafe | 7.5 |