LiveActive security incident?Get immediate response
CVE archive

September 2020

Browse CVE records published in September 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1721 matching CVEs · Page 7 of 35.

Medium · CVSS 4.3

CVE-2020-8339: A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced M...

A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web site, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the malicious web site. Impact is limited to the normal access restrictions of the user visiting the malicious web site, and subject to the user being logged into AMM, being able to connect to both AMM and the malicious web site while the web browser is open, and using a web browser that does not inherently protect against this class of attack. The JavaScript code is not executed on AMM itself.

Published Sep 15, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7727: Prototype Pollution

All versions of package gedi are vulnerable to Prototype Pollution via the set function.

Published Sep 1, 2020 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2020-9733: Sensitive information disclosure possible in AEM

An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.

Published Sep 10, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7723: Prototype Pollution

All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.

Published Sep 1, 2020 · Updated Sep 16, 2024

High · CVSS 7.2

CVE-2020-2038: PAN-OS: OS command injection vulnerability in the management web interface

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier than 9.1.4; PAN-OS 10.0 versions earlier than 10.0.1.

Published Sep 9, 2020 · Updated Sep 16, 2024

Critical · CVSS 9

CVE-2020-9740: Stored XSS in AEM Design Importer Component

AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

Published Sep 10, 2020 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2020-4521: IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrar...

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 182396.

Published Sep 15, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7730: Command Injection

The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.

Published Sep 4, 2020 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2020-14179: Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view...

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

Published Sep 21, 2020 · Updated Sep 16, 2024

Medium · CVSS 5.3

CVE-2020-36830: nescalante urlregex Backtracking index.js redos

A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of the component Backtracking. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.5.1 is able to address this issue. The identifier of the patch is e5a085afe6abfaea1d1a78f54c45af9ef43ca1f9. It is recommended to upgrade the affected component.

Published Sep 2, 2024 · Updated Sep 3, 2024

Unknown · CVSS Not scored

CVE-2020-27942: A logic issue was addressed with improved state management.

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may lead to arbitrary code execution.

Published Sep 8, 2021 · Updated Aug 4, 2024

High · CVSS 7.5

CVE-2020-26301: Command injection in mscdex/ssh2

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

Published Sep 20, 2021 · Updated Aug 4, 2024

Medium · CVSS 5.9

CVE-2020-26300: Command injection in systeminformation

systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.

Published Sep 9, 2021 · Updated Aug 4, 2024