Записи MuleSoft
6 опубликованных записей вендора mulesoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 33,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-502 Deserialization of Untrusted Data1
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-13116Эксплойта нет | The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserializatmulesoft · mule runtime · CWE-502 | Критическая9,8 | — | 5,1 % | 16 окт. 2019 г. |
40В плане | CVE-2019-15631Эксплойта нет | Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers mulesoft · api gateway | Критическая9,8 | — | 2,3 % | 1 дек. 2019 г. |
39Наблюдать | CVE-2020-10991Эксплойта нет | Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.javamulesoft · aplkit · CWE-611 | Критическая9,8 | — | 1,4 % | 26 мар. 2020 г. |
31Наблюдать | CVE-2019-15630Эксплойта нет | Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before Augumulesoft · api gateway · CWE-22 | Высокая7,5 | — | 3,0 % | 30 авг. 2019 г. |
30Наблюдать | CVE-2020-6937Эксплойта нет | A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers tmulesoft · mule runtime | Высокая7,5 | — | 1,2 % | 29 мая 2020 г. |
29Наблюдать | CVE-2014-9000Proof of concept | Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticatedmulesoft · mule enterprise management console · CWE-264 | Средняя6,5 | — | 8,9 % | 20 нояб. 2014 г. |
- CVE-2019-1311641В плане
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserializat
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mulesoft · mule runtime16 окт. 2019 г.
- CVE-2019-1563140В плане
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mulesoft · api gateway1 дек. 2019 г.
- CVE-2020-1099139Наблюдать
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mulesoft · aplkit26 мар. 2020 г.
- CVE-2019-1563031Наблюдать
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before Augu
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mulesoft · api gateway30 авг. 2019 г.
- CVE-2020-693730Наблюдать
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mulesoft · mule runtime29 мая 2020 г.
- CVE-2014-900029Наблюдать
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated
СредняяCVSS 6,5Proof of conceptEPSS 9 %mulesoft · mule enterprise management console20 нояб. 2014 г.