Symantec Identity Manager
Broadcom · 3 CVEs
CVE-2023-23951
MEDIUM
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
Jan 24, 2023
CVE-2023-23950
MEDIUM
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
Jan 24, 2023
CVE-2023-23949
HIGH
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
Jan 24, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-23951 | Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application | MEDIUM | 0.51% | Jan 24, 2023 |
| CVE-2023-23950 | User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. | MEDIUM | 0.51% | Jan 24, 2023 |
| CVE-2023-23949 | An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser. | HIGH | 0.56% | Jan 24, 2023 |
Showing 1 to 3 of 3 CVEs