Skip to main content

Vendor/product archive

vembu / bdr_suite CVEs

Beta · best-effort

5 CVEs tagged to vembu / bdr_suite3 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-43458

Published Apr 4, 2022

An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26474

Published Jun 8, 2021

Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26473

Published Jun 8, 2021

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the cont…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26471

Published Jun 8, 2021

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticate…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1