Vulnerabilities (CVE)

Filtered by vendor Visam Subscribe
Filtered by product Vbase
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45876 1 Visam 1 Vbase 2023-12-10 N/A 5.5 MEDIUM
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
CVE-2022-3217 1 Visam 1 Vbase 2023-12-10 N/A 7.5 HIGH
When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the ability to capture a login session can obtain the login credentials.