Записи softwareag
13 опубликованных записей вендора softwareag.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 7,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-502 Deserialization of Untrusted Data2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2019-13990Proof of concept | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descriptsoftwareag · quartz · CWE-611 | Критическая9,8 | — | 16,2 % | 26 июл. 2019 г. |
40В плане | CVE-2020-35469Эксплойта нет | The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.softwareag · terracotta server oss · CWE-306 | Критическая9,8 | — | 2,1 % | 15 дек. 2020 г. |
39Наблюдать | CVE-2021-33207Эксплойта нет | The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.softwareag · mashzone nextgen · CWE-502 | Критическая9,8 | — | 1,6 % | 4 апр. 2022 г. |
39Наблюдать | CVE-2023-39017Эксплойта нет | quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessagsoftwareag · quartz · CWE-94 | Критическая9,8 | — | 1,2 % | 28 июл. 2023 г. |
39Наблюдать | CVE-2023-0925Эксплойта нет | Software AG webMethods OneData Deserialization Vulnerabilitysoftwareag · webmethods · CWE-502 | Критическая9,8 | — | 0,8 % | 6 сент. 2023 г. |
29Наблюдать | CVE-2021-33523Эксплойта нет | MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can softwareag · mashzone nextgen | Высокая7,2 | — | 1,8 % | 30 мар. 2022 г. |
28Наблюдать | CVE-2021-33581Эксплойта нет | MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the fsoftwareag · mashzone nextgen · CWE-918 | Высокая7,2 | — | 1,3 % | 30 мар. 2022 г. |
28Наблюдать | CVE-2021-33208Эксплойта нет | The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configsoftwareag · mashzone nextgen · CWE-611 | Высокая7,2 | — | 1,2 % | 30 мар. 2022 г. |
27Наблюдать | CVE-2025-66837Proof of concept | A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malwaresoftwareag · aris · CWE-434 | Средняя6,8 | — | 0,3 % | 7 янв. 2026 г. |
26Наблюдать | CVE-2021-40649Эксплойта нет | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.softwareag · connx · CWE-732 | Средняя6,5 | — | 0,8 % | 14 июн. 2022 г. |
26Наблюдать | CVE-2021-40650Эксплойта нет | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.softwareag · connx · CWE-311 | Средняя6,5 | — | 0,8 % | 14 июн. 2022 г. |
26Наблюдать | CVE-2023-6578Эксплойта нет | Software AG WebMethods access controlsoftwareag · webmethods · CWE-284 | Средняя6,5 | — | 0,7 % | 7 дек. 2023 г. |
26Наблюдать | CVE-2025-66838Proof of concept | In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to uplsoftwareag · aris · CWE-770 | Средняя6,5 | — | 0,4 % | 7 янв. 2026 г. |
- CVE-2019-1399044В плане
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descript
КритическаяCVSS 9,8Proof of conceptEPSS 16 %softwareag · quartz26 июл. 2019 г.
- CVE-2020-3546940В плане
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %softwareag · terracotta server oss15 дек. 2020 г.
- CVE-2021-3320739Наблюдать
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %softwareag · mashzone nextgen4 апр. 2022 г.
- CVE-2023-3901739Наблюдать
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessag
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %softwareag · quartz28 июл. 2023 г.
- CVE-2023-092539Наблюдать
Software AG webMethods OneData Deserialization Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %softwareag · webmethods6 сент. 2023 г.
- CVE-2021-3352329Наблюдать
MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %softwareag · mashzone nextgen30 мар. 2022 г.
- CVE-2021-3358128Наблюдать
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the f
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %softwareag · mashzone nextgen30 мар. 2022 г.
- CVE-2021-3320828Наблюдать
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML config
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %softwareag · mashzone nextgen30 мар. 2022 г.
- CVE-2025-6683727Наблюдать
A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware
СредняяCVSS 6,8Proof of conceptEPSS 0 %softwareag · aris7 янв. 2026 г.
- CVE-2021-4064926Наблюдать
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %softwareag · connx14 июн. 2022 г.
- CVE-2021-4065026Наблюдать
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %softwareag · connx14 июн. 2022 г.
- CVE-2023-657826Наблюдать
Software AG WebMethods access control
СредняяCVSS 6,5Эксплойта нетEPSS 1 %softwareag · webmethods7 дек. 2023 г.
- CVE-2025-6683826Наблюдать
In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upl
СредняяCVSS 6,5Proof of conceptEPSS 0 %softwareag · aris7 янв. 2026 г.