Search Results (42 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-7417 1 Ericsson 1 Active Library Explorer 2024-11-21 N/A
XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter.
CVE-2024-25008 1 Ericsson 2 Controller 6610, Ran Compute 2024-08-19 6.8 Medium
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user having the system administrator role to exploit the vulnerability.