← Back

Impact

impact

Vendor: Nokia • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nokia
1Impact
Jun 17, 2026
Mar 3, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parame...Show more
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.Show less
1Nokia
1Impact
Jun 17, 2026
Mar 3, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via...Show more
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.Show less
1Nokia
1Impact
Jun 17, 2026
Mar 3, 2026
N/A· v4
4.1 MEDIUM· v3
N/A· v2
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This ca...Show more
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an authenticated user visits the web page where the file is published, the JavaScript code is executed.Show less
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Nokia IMPACT < 18A: has Reflected self XSS
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Nokia IMPACT < 18A: allows full path disclosure
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.