Skip to content
Noroxi

softwareag records

13 published records for vendor softwareag.

All records

13 records
  • initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descript

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    softwareag · quartzJul 26, 2019

  • The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.

    CriticalCVSS 9.8No exploitEPSS 2%

    softwareag · terracotta server ossDec 15, 2020

  • The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.

    CriticalCVSS 9.8No exploitEPSS 2%

    softwareag · mashzone nextgenApr 4, 2022

  • quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessag

    CriticalCVSS 9.8No exploitEPSS 1%

    softwareag · quartzJul 28, 2023

  • CVE-2023-0925
    39Monitor

    Software AG webMethods OneData Deserialization Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    softwareag · webmethodsSep 6, 2023

  • MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can

    HighCVSS 7.2No exploitEPSS 2%

    softwareag · mashzone nextgenMar 30, 2022

  • MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the f

    HighCVSS 7.2No exploitEPSS 1%

    softwareag · mashzone nextgenMar 30, 2022

  • The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML config

    HighCVSS 7.2No exploitEPSS 1%

    softwareag · mashzone nextgenMar 30, 2022

  • A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

    MediumCVSS 6.8Proof of conceptEPSS 0%

    softwareag · arisJan 7, 2026

  • In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

    MediumCVSS 6.5No exploitEPSS 1%

    softwareag · connxJun 14, 2022

  • In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

    MediumCVSS 6.5No exploitEPSS 1%

    softwareag · connxJun 14, 2022

  • CVE-2023-6578
    26Monitor

    Software AG WebMethods access control

    MediumCVSS 6.5No exploitEPSS 1%

    softwareag · webmethodsDec 7, 2023

  • In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upl

    MediumCVSS 6.5Proof of conceptEPSS 0%

    softwareag · arisJan 7, 2026