Nessus 的 Web Servers 系列

ID名称严重性
154966Draytek VigorConnect LFI (CVE-2021-20123)
high
154919SAP NetWeaver AS Java XXE 漏洞 (2296909)
medium
154918SAP NetWeaver AS Java 目录遍历漏洞 (2547431)
medium
154416Nacos < 1.4.1 身份验证绕过 (CVE-2021-29441)
critical
154340Oracle HTTP Server(2021 年 10 月 CPU)
medium
154151Apache Tomcat 10.0.0。M10 < 10.0.12
high
154150Apache Tomcat 9.0.40 < 9.0.54
high
154149Apache Tomcat 10.1.0.M1 < 10.1.0.M6
high
154147Apache Tomcat 8.5.60 < 8.5.72
high
154141SAP NetWeaver AS ABAP 多个漏洞(2021 年 10 月)
high
153952Apache 2.4.49 < 2.4.51 路径遍历漏洞
critical
153884Apache 2.4.49 < 2.4.50 多个漏洞
high
153587IBM WebSphere Application Server 信息泄露 (6489485)
medium
153586Apache >= 2.4.30 < 2.4.49 mod_proxy_uwsgi
high
153585Apache >= 2.4.17 < 2.4.49 mod_http2
high
153584Apache < 2.4.49 多种漏洞
critical
153583Apache < 2.4.49 多种漏洞
critical
153486Microsoft Open Management Infrastructure RCE (CVE-2021-38647)
critical
153474Microsoft Open Management Infrastructure < 1.6.8.1 多个漏洞
high
153441SAP NetWeaver AS 缺少授权检查(2021 年 9 月)
critical
152872VMware Workspace ONE UEM 控制台 DoS (VMSA-2021-0017)
high
152871PyDoc 中的 Python 信息泄露 (CVE-2021-3426)
medium
152782OpenSSL 1.1.1 < 1.1.1l 多个漏洞
critical
152780OpenSSL 1.0.2 < 1.0.2za 漏洞
high
152543Microsoft Azure CycleCloud 特权提升 (CVE-2021-33762)
high
152542Azure CycleCloud Web UI 检测
info
152541Microsoft Azure CycleCloud 特权提升 (CVE-2021-36943)
medium
152484GitLab Web UI 检测
info
152191IBM WebSphere Application Server 7.0.x <= 7.0.0.45 / 8.0.x <= 8.0.0.14 / 8.5.x < 8.5.5.21 / 9.0.x < 9.0.5.9 特权提升
high
152183Apache Tomcat 8.5.0 < 8.5.68
medium
152182Apache Tomcat 9.0.0.M1 < 9.0.48
medium
152120SAP NetWeaver AS ABAP 内存损坏(2021 年 7 月)
medium
152096SAP NetWeaver AS 缺少授权检查 (3059446)
high
151808SAP NetWeaver AS ABAP 代码注入 (3048657)
medium
151791TeamCity Server < 2020.2.4 多个漏洞
critical
151762SAP NetWeaver AS ABAP 和 ABAP 信息泄露 (3044754)
high
151663Java 版 SAP NetWeaver AS DoS (3056652)
high
151504Apache Tomcat 10.0.3 < 10.0.5
high
151502Apache Tomcat 10.0.0.M1 < 10.0.6
medium
151501Apache Tomcat 10.0.0.M1 < 10.0.7
medium
150946Apache Tomcat 10.0.0.M1 < 10.0.0.M5
high
150938Apache Tomcat 10.0.0.M1 < 10.0.0.M6
high
150937Apache Tomcat 10.0.0.M1 < 10.0.0.M10 多个漏洞
high
150936Apache Tomcat 10.0.0.M1 < 10.0.0.M7 多个漏洞
high
150935Apache Tomcat 10.0.0.M1 < 10.0.0.M8
medium
150856Apache Tomcat 10.0.0.M1 < 10.0.2 多个漏洞
high
150787SAP NetWeaver AS JAVA 信息泄露 (3023299)
medium
150753SAP NetWeaver AS ABAP 跨站脚本 (XSS)(2021 年 6 月)
medium
150719SAP NetWeaver AS ABAP 命令注入(2021 年 6 月)
medium
150718SAP NetWeaver AS JAVA 缺少 XML 验证 (3053066)
medium