Home/Product/redhat 3scale api management
Product

redhat 3scale api management

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-10295
all versions
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authentica
7.5HIGH
CVE-2023-4910
all versions
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the
5.5MEDIUM
CVE-2022-1414
all versions
3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use th
8.8HIGH
CVE-2022-0330
all versions
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicio
7.8HIGH
CVE-2021-3656
all versions
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual
8.8HIGH
CVE-2021-3609
all versions
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsy
7.0HIGH
CVE-2020-14388
all versions
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not proper
6.3MEDIUM
CVE-2021-3412
all versions
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass
7.3HIGH
CVE-2020-25634
all versions
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to v
5.4MEDIUM
CVE-2019-14852
all versions
A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weak
7.5HIGH
CVE-2021-20252
all versions
A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requ
6.5MEDIUM
CVE-2019-10216
all versions
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to by
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin