MuleSoft records
6 published records for vendor mulesoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-502 Deserialization of Untrusted Data1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2019-13116No exploit | The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserializatmulesoft · mule runtime · CWE-502 | Critical9.8 | — | 5.1% | Oct 16, 2019 |
40Plan | CVE-2019-15631No exploit | Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers mulesoft · api gateway | Critical9.8 | — | 2.3% | Dec 1, 2019 |
39Monitor | CVE-2020-10991No exploit | Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.javamulesoft · aplkit · CWE-611 | Critical9.8 | — | 1.4% | Mar 26, 2020 |
31Monitor | CVE-2019-15630No exploit | Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before Augumulesoft · api gateway · CWE-22 | High7.5 | — | 3.0% | Aug 30, 2019 |
30Monitor | CVE-2020-6937No exploit | A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers tmulesoft · mule runtime | High7.5 | — | 1.2% | May 29, 2020 |
29Monitor | CVE-2014-9000Proof of concept | Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticatedmulesoft · mule enterprise management console · CWE-264 | Medium6.5 | — | 8.9% | Nov 20, 2014 |
- CVE-2019-1311641Plan
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserializat
CriticalCVSS 9.8No exploitEPSS 5%mulesoft · mule runtimeOct 16, 2019
- CVE-2019-1563140Plan
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers
CriticalCVSS 9.8No exploitEPSS 2%mulesoft · api gatewayDec 1, 2019
- CVE-2020-1099139Monitor
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
CriticalCVSS 9.8No exploitEPSS 1%mulesoft · aplkitMar 26, 2020
- CVE-2019-1563031Monitor
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before Augu
HighCVSS 7.5No exploitEPSS 3%mulesoft · api gatewayAug 30, 2019
- CVE-2020-693730Monitor
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers t
HighCVSS 7.5No exploitEPSS 1%mulesoft · mule runtimeMay 29, 2020
- CVE-2014-900029Monitor
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated
MediumCVSS 6.5Proof of conceptEPSS 9%mulesoft · mule enterprise management consoleNov 20, 2014