← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jun 16, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OX App Suite through 7.10.3 allows SSRF.
1Digdash
1Digdash
Jun 17, 2026
Jun 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an externa...Show more
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application credentials. For a request to an internal component, the request is blind, but through the error message it's possible to determine whether the request targeted a open service.Show less
1Open Xchange
1Ox Guard
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
OX Guard 2.10.3 and earlier allows SSRF.
1Apache
1Karaf
Jun 17, 2026
Jun 12, 2020
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on an MBean. However there is a vulnerability there for someone who is no...Show more
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on an MBean. However there is a vulnerability there for someone who is not an admin, but has a "viewer" role. In the 'etc/jmx.acl.cfg', such as role can call get*. It's possible to authenticate as a viewer role + invokes on the MLet getMBeansFromURL method, which goes off to a remote server to fetch the desired MBean, which is then registered in Karaf. At this point the attack fails as "viewer" doesn't have the permission to invoke on the MBean. Still, it could act as a SSRF style attack and also it essentially allows a "viewer" role to pollute the MBean registry, which is a kind of privilege escalation. The vulnerability is low as it's possible to add a ACL to limit access. Users should update to Apache Karaf 4.2.9 or newer.Show less
1Adobe
1Experience Manager
Jun 17, 2026
Jun 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Adobe
1Experience Manager
Jun 17, 2026
Jun 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Redash
1Redash
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a l...Show more
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a lot of flexibility in terms of being able to craft HTTP requests e.g., by adding headers, selecting any HTTP verb, etc.Show less
1Hcltech
1Hcl Digital Experience
Jun 17, 2026
Jun 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
"HCL Digital Experience is susceptible to Server Side Request Forgery."
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Jun 10, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing mali...Show more
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious server. Furthermore, if NTLM is setup the attacker can compromise confidentiality, integrity and availability of the SAP database.Show less
1Ibm
1Maximo Asset Management
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.4 HIGH· v3
6.5 MEDIUM· v2
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enum...Show more
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.Show less
2Fedoraproject
Kubernetes
2Fedora
Kubernetes
Jun 17, 2026
Jun 5, 2020
N/A· v4
6.3 MEDIUM· v3
3.5 LOW· v2
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users...Show more
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).Show less
4Fedoraproject
GrafanaNetapp+1 more
5Backports Sle
E Series Performance AnalyzerFedora+2 more
Jun 17, 2026
Jun 3, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result...Show more
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.Show less
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
1Wso2
1Api Manager
Jun 17, 2026
May 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
1Ibm
1Websphere Application Server
Jun 17, 2026
May 14, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-...Show more
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.Show less
1Commscope
1Ruckus Zoneflex R500 Firmware
Jun 17, 2026
May 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
1Cybozu
1Garoon
Jun 17, 2026
Apr 28, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an administrative privilege to issue arbitrary HTTP requests to other web servers via V-CUBE Meeting function...Show more
Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an administrative privilege to issue arbitrary HTTP requests to other web servers via V-CUBE Meeting function.Show less
1Wso2
1Enterprise Integrator
Jun 17, 2026
Apr 17, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or...Show more
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 176404.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.