Ericsson
ericsson
44 CVEs • 19 products
Products (19)
Click to collapseToggle
Products (19)
Click to collapse
CVEs (44)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser...Show more |
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An attac...Show more |
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or in...Show more |
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application. |
An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass system CLI and execute commands they are authorized to execute directly...Show more |
1Ericsson 1Mobile Switching Center Server Bc 18a Firmware Jun 17, 2026 Sep 14, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to fil...Show more |
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote co...Show more |
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out...Show more |
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in EN...Show more |
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS auth...Show more |
In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON d...Show more |
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created. |
1Ericsson 1Operations Support System Radio And Core Firmware Jun 17, 2026 Oct 14, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only....Show more |
1Ericsson 1Operations Support System Radio And Core Firmware Jun 17, 2026 Oct 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting. This problem is completely resolved in new Ericsson library browsing tool ELEX used...Show more |
1Ericsson 1Enterprise Content Management Jun 17, 2026 Sep 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover. |
1Ericsson 1Enterprise Content Management Jun 17, 2026 Sep 17, 2021 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection. |
1Ericsson 2Bscs Ix R18 Billing & Rating Admx Bscs Ix R18 Billing & Rating MxJun 17, 2026 Nov 27, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceDataSU Access Rights G...Show more |
1Ericsson 2Bscs Ix R18 Billing & Rating Admx Bscs Ix R18 Billing & Rating MxJun 17, 2026 Nov 27, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also possible by utilizing th...Show more |
1Ericsson 1Active Library Explorer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter. |
1Ericsson 1Drutt Mobile Service Delivery Platform May 6, 2026 Apr 6, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open redirect vulnerability in the 3PI Manager in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL...Show more |