Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LongBox Access Manager 信息泄露漏洞
Vulnerability Description
LongBox Access Manager是一款访问管理软件。 LongBox Access Manager 1.2版本至1.4-RG3版本中存在安全漏洞。远程攻击者可利用该漏洞枚举内部Active Directory用户名并可能枚举Active Directory组群名及更改后端服务器的任务。
CVSS Information
N/A
Vulnerability Type
N/A