Basware / Banking
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-6747 | Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks vi… | MEDIUM | 5.0 | Aug 31, 2015 |
| CVE-2015-6746 | Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications wi… | LOW | 2.1 | Aug 31, 2015 |
| CVE-2015-6745 | Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleti… | MEDIUM | 4.6 | Aug 31, 2015 |
| CVE-2015-6744 | Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, whi… | MEDIUM | 4.3 | Aug 31, 2015 |
| CVE-2015-6743 | Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote authenticated users to bypass intended acce… | MEDIUM | 6.5 | Aug 31, 2015 |
| CVE-2015-6742 | Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended acc… | MEDIUM | 6.5 | Aug 31, 2015 |
| CVE-2015-0943 | Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attack… | MEDIUM | 5.8 | Aug 31, 2015 |
Showing 1 to 7 of 7 CVEs