[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-6967":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":73,"vuln_id":87,"name":88,"published":89,"updated":74},6967,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":71,"name":72},3,"OpenVAS",{"id":65,"codename":74,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":74,"references":79,"cvssv3":82,"epss_score":83,"epss_percentile":84,"cve":85,"in_cisa_catalog":9,"date":74,"software_type":74,"vendor":74,"product":74,"ptt_exploit_capabilities":74},null,"critical","OrientDB uses RBAC model for authentication schemes. By default an OrientDB has 3 roles - admin, writer and reader. These have their usernames same as the role. For each database created on the server, it assigns by default these 3 users. The privileges of the users are: admin - access to all functions on the database without any limitation reader - read-only user. The reader can query any records in the database, but cant modify or delete them. It has no access to internal information, such as the users and roles themselves writer - same as the reader, but it can also create, update and delete records ORole structure handles users and their roles and is only accessible by the admin user. OrientDB requires oRole read permissions to allow the user to display the permissions of users and make other queries associated with oRole permissions. From version 2.2.x and above whenever the oRole is queried with a where, fetchplan and order by statements, this permission requirement is not required and information is returned to unprivileged users. Since OrientDB has a function where one could execute groovy functions and this groovy wrapper doesnt have a sandbox and exposes system functionalities, it is possible to run any command.","OrientDB does not enforce privilege requirements during where or fetchplan or order by use, which allows remote attackers to execute arbitrary OS commands via a crafted request.","Update to version 2.2.23 or later.",[80,81],"http:\u002F\u002Fwww.heavensec.org\u002F?p=1703","https:\u002F\u002Fgithub.com\u002Forientechnologies\u002Forientdb\u002Fwiki\u002FOrientDB-2.2-Release-Notes#2223---july-11-2017",9.8,0.73071,0.99431,[86],"CVE-2017-11467","NETSCAN-OPENVAS-1.3.6.1.4.1.25623.1.0.112079","OrientDB Server 2.2.x \u003C= 2.2.22 RCE Vulnerability","2018-01-02T00:00:00Z"]