VendorsBPCBTsmartvista2
Vulnerabilities

BPCBT SmartVista 2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-15206
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
Published 2019-04-30 · Modified
8.8EPSS 0.006
CVE-2018-15208
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
Published 2019-04-30 · Modified
7.5EPSS 0.011
CVE-2018-15207
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.
Published 2019-04-30 · Modified
7.2EPSS 0.014