Issues
- Server name/version number exposed in the response headerNMS-16452Resolved issue: NMS-16452Christian Pape
- [Web] - Missing Secure Flag on Session CookieNMS-16451Resolved issue: NMS-16451Christian Pape
- Host Header InjectionNMS-16450Resolved issue: NMS-16450Christian Pape
- Detailed server configuration in the errorNMS-16449Resolved issue: NMS-16449Christian Pape
- Stored XSS on "Node Label"NMS-16448Resolved issue: NMS-16448Christian Pape
- Missing Access Control on "Geocoder Configuration"NMS-16447Resolved issue: NMS-16447Christian Pape
- Missing Access Control on "Grafana Endpoints"NMS-16446Resolved issue: NMS-16446Christian Pape
- Stored XSS on "Scheduled Outages"NMS-16445Resolved issue: NMS-16445Christian Pape
- Stored XSS on "MIB Compiler"NMS-16444Resolved issue: NMS-16444Christian Pape
- Stored XSS on "Monitoring Locations"NMS-16443Resolved issue: NMS-16443Christian Pape
- Missing Access Control on Geocoder Configuration.NMS-14025
- Self XSS via User-AgentNMS-14024
- Improper Error HandlingNMS-14020
- Stored XSS On-Call Roles.NMS-14010
- Weak Basic Authentication Protocol UsedNMS-14009
- Stored XSS on Quick-Add NodeNMS-14001
- Stored XSS in Discovery configurationNMS-13995
- [Web] - WebServer FingerprintingNMS-13987Resolved issue: NMS-13987Dmitri Herdt
- [Web] - Vulnerable Angular JS version in UseNMS-13986
- [Web] - Missing Secure & HTTP Only Flags on Session CookieNMS-13985
- [Web] - Session Fixation/Misconfigured Session Cookie ImplementationNMS-13984
- [Web] - Password field with autocomplete enabled on Login pageNMS-13983Resolved issue: NMS-13983Lars Schreiber
- [Web] - Inadequate Account Lockout PolicyNMS-13982
- [Web] - Weak Password PolicyNMS-13981Resolved issue: NMS-13981Lars Schreiber
- Internal Port Scan using SSRFNMS-13980
- Open Redirect using Host Header InjectionNMS-13979
- Server Banner DisclosureNMS-13976
27 of 27