softwareag records
13 published records for vendor softwareag.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 7.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2019-13990Proof of concept | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descriptsoftwareag · quartz · CWE-611 | Critical9.8 | — | 16.2% | Jul 26, 2019 |
40Plan | CVE-2020-35469No exploit | The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.softwareag · terracotta server oss · CWE-306 | Critical9.8 | — | 2.1% | Dec 15, 2020 |
39Monitor | CVE-2021-33207No exploit | The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.softwareag · mashzone nextgen · CWE-502 | Critical9.8 | — | 1.6% | Apr 4, 2022 |
39Monitor | CVE-2023-39017No exploit | quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessagsoftwareag · quartz · CWE-94 | Critical9.8 | — | 1.2% | Jul 28, 2023 |
39Monitor | CVE-2023-0925No exploit | Software AG webMethods OneData Deserialization Vulnerabilitysoftwareag · webmethods · CWE-502 | Critical9.8 | — | 0.8% | Sep 6, 2023 |
29Monitor | CVE-2021-33523No exploit | MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can softwareag · mashzone nextgen | High7.2 | — | 1.8% | Mar 30, 2022 |
28Monitor | CVE-2021-33581No exploit | MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the fsoftwareag · mashzone nextgen · CWE-918 | High7.2 | — | 1.3% | Mar 30, 2022 |
28Monitor | CVE-2021-33208No exploit | The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configsoftwareag · mashzone nextgen · CWE-611 | High7.2 | — | 1.2% | Mar 30, 2022 |
27Monitor | CVE-2025-66837Proof of concept | A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malwaresoftwareag · aris · CWE-434 | Medium6.8 | — | 0.3% | Jan 7, 2026 |
26Monitor | CVE-2021-40649No exploit | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.softwareag · connx · CWE-732 | Medium6.5 | — | 0.8% | Jun 14, 2022 |
26Monitor | CVE-2021-40650No exploit | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.softwareag · connx · CWE-311 | Medium6.5 | — | 0.8% | Jun 14, 2022 |
26Monitor | CVE-2023-6578No exploit | Software AG WebMethods access controlsoftwareag · webmethods · CWE-284 | Medium6.5 | — | 0.7% | Dec 7, 2023 |
26Monitor | CVE-2025-66838Proof of concept | In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to uplsoftwareag · aris · CWE-770 | Medium6.5 | — | 0.4% | Jan 7, 2026 |
- CVE-2019-1399044Plan
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descript
CriticalCVSS 9.8Proof of conceptEPSS 16%softwareag · quartzJul 26, 2019
- CVE-2020-3546940Plan
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.
CriticalCVSS 9.8No exploitEPSS 2%softwareag · terracotta server ossDec 15, 2020
- CVE-2021-3320739Monitor
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
CriticalCVSS 9.8No exploitEPSS 2%softwareag · mashzone nextgenApr 4, 2022
- CVE-2023-3901739Monitor
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessag
CriticalCVSS 9.8No exploitEPSS 1%softwareag · quartzJul 28, 2023
- CVE-2023-092539Monitor
Software AG webMethods OneData Deserialization Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%softwareag · webmethodsSep 6, 2023
- CVE-2021-3352329Monitor
MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can
HighCVSS 7.2No exploitEPSS 2%softwareag · mashzone nextgenMar 30, 2022
- CVE-2021-3358128Monitor
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the f
HighCVSS 7.2No exploitEPSS 1%softwareag · mashzone nextgenMar 30, 2022
- CVE-2021-3320828Monitor
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML config
HighCVSS 7.2No exploitEPSS 1%softwareag · mashzone nextgenMar 30, 2022
- CVE-2025-6683727Monitor
A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware
MediumCVSS 6.8Proof of conceptEPSS 0%softwareag · arisJan 7, 2026
- CVE-2021-4064926Monitor
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
MediumCVSS 6.5No exploitEPSS 1%softwareag · connxJun 14, 2022
- CVE-2021-4065026Monitor
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
MediumCVSS 6.5No exploitEPSS 1%softwareag · connxJun 14, 2022
- CVE-2023-657826Monitor
Software AG WebMethods access control
MediumCVSS 6.5No exploitEPSS 1%softwareag · webmethodsDec 7, 2023
- CVE-2025-6683826Monitor
In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upl
MediumCVSS 6.5Proof of conceptEPSS 0%softwareag · arisJan 7, 2026