Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-08-12
Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
CVSS Score
9.8
EPSS Score
0.004
Published
2026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input.
CVSS Score
4.3
EPSS Score
0.004
Published
2026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
CVSS Score
4.3
EPSS Score
0.003
Published
2026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an interpretation conflict in the multipart parser.
CVSS Score
3.0
EPSS Score
0.002
Published
2026-08-12
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
CVSS Score
8.8
EPSS Score
0.008
Published
2026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
CVSS Score
8.8
EPSS Score
0.002
Published
2026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
CVSS Score
4.3
EPSS Score
0.003
Published
2026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
CVSS Score
8.3
EPSS Score
0.004
Published
2026-08-12


Contact Us

Shodan ® - All rights reserved