Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Imperva/
  3. Imperva Advanced Bot Protection

Imperva Advanced Bot Protection

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 18 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Bot protection for websites, mobile apps, and APIs against automated threats

by Imperva · imperva.com · source ↗

Known CVEs (18)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2023-50969 ↗CRITICAL 9.82024

    Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.

  • CVE-2023-40180 ↗HIGH 7.52023

    silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS at…

  • CVE-2021-45468 ↗CRITICAL 9.82022

    Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to…

  • CVE-2011-5266 ↗CRITICAL 9.82020

    Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.

  • CVE-2018-16660 ↗HIGH 8.82019

    A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installat…

  • CVE-2018-5413 ↗HIGH 8.82019

    Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.

  • CVE-2018-5412 ↗HIGH 7.82019

    Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.

  • CVE-2018-5403 ↗HIGH 8.12019

    Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE t…

  • CVE-2018-19646 ↗CRITICAL 9.82018

    The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.

  • CVE-2011-4887 ↗MEDIUM 4.32014

    Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to…

  • CVE-2013-4095 ↗MEDIUM 6.52013

    plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a […

  • CVE-2013-4094 ↗MEDIUM 6.52013

    The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) priva…

  • CVE-2013-4093 ↗MEDIUM 5.02013

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information via (1) a direct request to dwr/call/plaincall/Async…

  • CVE-2013-4092 ↗MEDIUM 5.02013

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive information by leveraging the presence of (1) a sessi…

  • CVE-2013-4091 ↗HIGH 7.52013

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp l…

  • CVE-2011-0767 ↗MEDIUM 4.32011

    Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall 6.2, 7.x, and 8.x allows remote attackers to inject arbitrar…

  • CVE-2010-1329 ↗HIGH 7.82010

    Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusion-prevention functionality via a request that has an appended…

  • CVE-2008-1463 ↗MEDIUM 4.32008

    Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibi…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other WAF / DDoS / App Protection products

see all →
  • A10 Networks ThreatX · A10 Networks
  • AI Bot Management · Fastly
  • Advanced Bot Protection · Imperva
  • Akamai App & API Protector · Akamai
  • Akamai Bot & Abuse Protection · Akamai
  • Akamai Bot Manager · Akamai
  • Akamai Edge DNS · Akamai
  • Akamai Prolexic · Akamai