abacus records
2 published records for vendor abacus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-304 Missing Critical Step in Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-1065No exploit | Multi Factor Authentication Bypass in various versions of Abacus ERPabacus · abacus erp 2018 · CWE-304 | High8.8 | — | 2.9% | Apr 19, 2022 |
24Monitor | CVE-2019-19381No exploit | oauth/oauth2/v1/saml/ in Abacus OAuth Login 2019_01_r4_20191021_0000 before prior to R4 (20.11.2019 Hotfix) allows Reflected Cross Site Scriabacus · abacus · CWE-79 | Medium6.1 | — | 0.7% | Mar 11, 2020 |
- CVE-2022-106536Monitor
Multi Factor Authentication Bypass in various versions of Abacus ERP
HighCVSS 8.8No exploitEPSS 3%abacus · abacus erp 2018Apr 19, 2022
- CVE-2019-1938124Monitor
oauth/oauth2/v1/saml/ in Abacus OAuth Login 2019_01_r4_20191021_0000 before prior to R4 (20.11.2019 Hotfix) allows Reflected Cross Site Scri
MediumCVSS 6.1No exploitEPSS 1%abacus · abacusMar 11, 2020