LiveActive security incident?Get immediate response
CVE archive

December 2021

Browse CVE records published in December 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2052 matching CVEs · Page 8 of 42.

Medium · CVSS 6.1

CVE-2021-38876: IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting.

IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.

Published Dec 30, 2021 · Updated Sep 17, 2024

Medium · CVSS 6.5

CVE-2021-23561: Prototype Pollution

All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.

Published Dec 10, 2021 · Updated Sep 17, 2024

Critical · CVSS 9.8

CVE-2021-23639: Remote Code Execution (RCE)

The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

Published Dec 10, 2021 · Updated Sep 17, 2024

Medium · CVSS 4.7

CVE-2021-34425: Server Side Request Forgery in Zoom Client for Meetings chat

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "link preview" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.

Published Dec 14, 2021 · Updated Sep 17, 2024

Medium · CVSS 6.4

CVE-2021-38893: IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are...

IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209512.

Published Dec 21, 2021 · Updated Sep 17, 2024

Medium · CVSS 5.4

CVE-2021-29849: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting.

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205281.

Published Dec 1, 2021 · Updated Sep 17, 2024

High · CVSS 7.2

CVE-2021-40853: TCMAN GIM missing authorization vulnerability

TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to obtain sensible information.

Published Dec 17, 2021 · Updated Sep 17, 2024

Critical · CVSS 10

CVE-2021-22657: mySCADA myPRO

mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

Published Dec 23, 2021 · Updated Sep 17, 2024

Critical · CVSS 9

CVE-2021-40333: Weak default credential associated with TCP port 26

Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.

Published Dec 2, 2021 · Updated Sep 17, 2024

Critical · CVSS 9.8

CVE-2021-44159: 4MOSAn GCB Doctor - Unrestricted Upload of File

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

Published Dec 20, 2021 · Updated Sep 17, 2024

Medium · CVSS 5.9

CVE-2021-39053: IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive info...

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Data Management Admin Console. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 214524.

Published Dec 13, 2021 · Updated Sep 17, 2024

Critical · CVSS 9.8

CVE-2021-43987: mySCADA myPRO

An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.

Published Dec 23, 2021 · Updated Sep 16, 2024

Critical · CVSS 10

CVE-2021-43984: mySCADA myPRO

mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

Published Dec 23, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-44471: Delta Electronics DIAEnergie (Update A)

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.

Published Dec 22, 2021 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2021-29863: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF).

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This vulnerability is due to an incomplete fix for CVE-2020-4786. IBM X-Force ID: 206087.

Published Dec 1, 2021 · Updated Sep 16, 2024

Critical · CVSS 9.6

CVE-2021-36779: Host operations allowed in privileged Longhorn managed pods

A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.

Published Dec 17, 2021 · Updated Sep 16, 2024

High · CVSS 8.1

CVE-2021-36780: Unauthorized data access from replicas through vulnerable instance manager pods

A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3v.

Published Dec 17, 2021 · Updated Sep 16, 2024

High · CVSS 7.3

CVE-2021-44160: Carinal Tien Hospital Health Report System - Authorization Bypass Through User-Controlled Key

Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.

Published Dec 29, 2021 · Updated Sep 16, 2024

High · CVSS 8.6

CVE-2021-40334: SSH activation problem in the proprietary management protocol (port TCP 5558)

Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.

Published Dec 2, 2021 · Updated Sep 16, 2024

High · CVSS 8.1

CVE-2021-43935: ICSMA-21-343-01 Hillrom Welch Allyn Cardio Products

The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.

Published Dec 15, 2021 · Updated Sep 16, 2024

High · CVSS 8.1

CVE-2021-39065: IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary com...

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system. IBM X-Force ID: 214958.

Published Dec 13, 2021 · Updated Sep 16, 2024

High · CVSS 7.1

CVE-2021-38688: Improper Authentication in Qfile

An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later

Published Dec 29, 2021 · Updated Sep 16, 2024

Medium · CVSS 4.2

CVE-2021-23258: Spring SPEL Expression Language Injection

Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).

Published Dec 2, 2021 · Updated Sep 16, 2024

High · CVSS 7.8

CVE-2021-4007: Rapid7 Insight Agent Privilege Escalation

Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally authenticated users. Because of this, a malicious local user could use Insight Agent's startup conditions to elevate to SYSTEM privileges. This issue was fixed in Rapid7 Insight Agent 3.1.2.35. This vulnerability is a regression of CVE-2019-5629.

Published Dec 14, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.1

CVE-2021-38961: IBM OPENBMC OP910 is vulnerable to cross-site scripting.

IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212049.

Published Dec 27, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2021-23700: Prototype Pollution

All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.

Published Dec 10, 2021 · Updated Sep 16, 2024

High · CVSS 7.1

CVE-2021-43051: TIBCO Spotfire Server API Authorization Vulnerability

The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows malicious custom API clients with network access to execute internal API operations outside of the scope of those granted to it. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Server: versions 10.10.6 and below, TIBCO Spotfire Server: versions 11.0.0, 11.1.0, 11.2.0, 11.3.0, 11.4.0, and 11.4.1, and TIBCO Spotfire Server: versions 11.5.0 and 11.6.0.

Published Dec 14, 2021 · Updated Sep 16, 2024