CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,758 vulnerabilities with CWE-918
CVE-2019-12633 HIGH
Cisco Unified Contact Center Express - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2019-12632 HIGH
Cisco Finesse - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2019-13020 CRITICAL
Tightrope Media Carousel < 7.1.3 - Unauthenticated Server-Side Request Forgery via Fetch API
CVSS 10.0
CVE-2019-15494 CRITICAL
openITCOCKPIT < 3.7.1 - Server-Side Request Forgery
CVSS 9.8
CVE-2019-11897 HIGH
ProSyst mBS SDK <8.2.6 & Bosch IoT Gateway Software <9.3.0 - SSRF
CVSS 8.6
CVE-2019-0345 CRITICAL
SAP NetWeaver Application Server Java 7.30, 7.31, 7.40, 7.50 - Unauthenticated Server-Side Request Forgery via XML File
CVSS 9.8
CVE-2019-12994 CRITICAL
ManageEngine AssetExplorer 6.2.0 - Server-Side Request Forgery via AJaxServlet Parameter
CVSS 9.1
CVE-2019-12959 HIGH
ManageEngine AssetExplorer < 6.2.0 - Server-Side Request Forgery via ClientUtilServlet URL Parameter
CVSS 8.8
CVE-2019-14255 CRITICAL
go-camo < 1.1.4 - Server-Side Request Forgery
CVSS 9.8
CVE-2019-14704 CRITICAL
MicroDigital N-series <6400.0.8.5 - SSRF
CVSS 9.8
CVE-2019-7923 HIGH
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Authenticated Server-Side Request Forgery in Shipment Settings
CVSS 7.2
CVE-2019-7913 HIGH
Magento 2.1.0-2.1.17 - Authenticated Server-Side Request Forgery via Shipment Method Manipulation
CVSS 7.2
CVE-2019-7911 HIGH
Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - SSRF
CVSS 7.2
CVE-2019-7892 HIGH
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Authenticated Remote Code Execution via Server-Side Request Forgery
CVSS 7.2
CVE-2019-7616 MEDIUM
Kibana < 6.8.2 - Authenticated Server-Side Request Forgery via Timelion Graphite URL Configuration
CVSS 4.9
CVE-2019-9827 CRITICAL
Hawt Hawtio < 2.5.0 - Server-Side Request Forgery via Proxy URI
CVSS 9.8
CVE-2019-12852 CRITICAL
JetBrains YouTrack < 2018.4.49168 - Server-Side Request Forgery
CVSS 9.8
CVE-2019-12153 CRITICAL
RealObjects PDFreactor <10.1.10722 - SSRF
CVSS 10.0
CVE-2019-9187 HIGH
ikiwiki < 3.20170111.1, 3.2018x, < 3.20190228 - Server-Side Request Forgery via Aggregate Plugin
CVSS 7.5
CVE-2019-1872 MEDIUM
Cisco TelePresence Video Communication Server - DoS
CVSS 5.3
CVE-2019-6981 MEDIUM
Zimbra Collaboration Suite <8.9 - Blind SSRF
CVSS 6.5
CVE-2019-12161 HIGH
webpagetest 19.04 - Server-Side Request Forgery via Octal IP Address Encoding
CVSS 8.8
CVE-2019-6516 MEDIUM
WSO2 Dashboard Server 2.0.0 - Server-Side Request Forgery
CVSS 5.8
CVE-2019-6512 MEDIUM
WSO2 API Manager 2.6.0 - Server-Side Request Forgery via file:// Wrapper
CVSS 4.1
CVE-2019-11066 CRITICAL
LightOpenID < 1.3.1 - Server-Side Request Forgery via OpenID 2.0 Assertion Request
CVSS 9.8
Details
Vulnerabilities 2,758