Vulnerabilities (CVE)

Filtered by CWE-435
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-43052 1 Ibm 1 Control Center 2025-06-19 N/A 5.3 MEDIUM
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with.
CVE-2020-2287 1 Jenkins 1 Audit Trail 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.