Riverbed
riverbed
17 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (17)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured to use local, RADIUS, or TACACS authentication) logs usernames and pass...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not h...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to cra...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is s...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endp...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected e...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validati...Show more |
1Riverbed 1Steelcentral Aternity Agent Jun 17, 2026 Jul 27, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes f...Show more |
1Riverbed 1Steelcentral Aternity Agent Jun 17, 2026 Jul 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data...Show more |
27Anynines ApigeeAppdynamics+24 more55Application Analytics Application MonitoringApplication Performance Monitoring+52 moreJun 17, 2026 Aug 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more |
1Riverbed 1Opnet App Response Xpert May 13, 2026 Aug 26, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated users to inject arbitrary commands to read OS files. |
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/t...Show more |
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the passwo...Show more |
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes t...Show more |
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks. |
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or...Show more |