NICE records
3 published records for vendor nice.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-7727No exploit | In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restrictnice · engage · CWE-306 | Critical9.8 | — | 3.9% | Apr 23, 2019 |
31Monitor | CVE-2014-4305No exploit | Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote attackers to executenice · recording express · CWE-89 | High7.5 | — | 1.9% | Jun 18, 2014 |
17Monitor | CVE-2014-4308No exploit | Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers tonice · recording express · CWE-79 | Medium4.3 | — | 1.4% | Jun 18, 2014 |
- CVE-2019-772740Plan
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restrict
CriticalCVSS 9.8No exploitEPSS 4%nice · engageApr 23, 2019
- CVE-2014-430531Monitor
Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote attackers to execute
HighCVSS 7.5No exploitEPSS 2%nice · recording expressJun 18, 2014
- CVE-2014-430817Monitor
Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to
MediumCVSS 4.3No exploitEPSS 1%nice · recording expressJun 18, 2014