ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-36120
+1 in the same advisory: …36121
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01.

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a low/no privilege Blue Prism user account, the attacker can alter the server's settings by abusing the getChartData method, allowing the Blue Prism server to execute any MSSQL stored procedure by name.

NVD description · AI analysis pending
8.1
group max
<1%
  • ssctech blue prism enterprise
CVE-2022-36119
+4 in the same advisory: …36115 …36116 …36118 …36117
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01.

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of insecure deserialization. Exploitation of this vulnerability allows for code to be executed in the context of the Blue Prism Server service.

NVD description · AI analysis pending
8.8
group max
2%
  • ssctech blue prism