Перейти к содержимому
Noroxi

Записи softwareag

13 опубликованных записей вендора softwareag.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
7,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

13 записей
  • CVE-2019-13990
    44В плане

    initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descript

    КритическаяCVSS 9,8Proof of conceptEPSS 16 %

    softwareag · quartz26 июл. 2019 г.

  • CVE-2020-35469
    40В плане

    The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    softwareag · terracotta server oss15 дек. 2020 г.

  • CVE-2021-33207
    39Наблюдать

    The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    softwareag · mashzone nextgen4 апр. 2022 г.

  • CVE-2023-39017
    39Наблюдать

    quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessag

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    softwareag · quartz28 июл. 2023 г.

  • CVE-2023-0925
    39Наблюдать

    Software AG webMethods OneData Deserialization Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    softwareag · webmethods6 сент. 2023 г.

  • CVE-2021-33523
    29Наблюдать

    MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    softwareag · mashzone nextgen30 мар. 2022 г.

  • CVE-2021-33581
    28Наблюдать

    MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the f

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    softwareag · mashzone nextgen30 мар. 2022 г.

  • CVE-2021-33208
    28Наблюдать

    The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML config

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    softwareag · mashzone nextgen30 мар. 2022 г.

  • CVE-2025-66837
    27Наблюдать

    A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

    СредняяCVSS 6,8Proof of conceptEPSS 0 %

    softwareag · aris7 янв. 2026 г.

  • CVE-2021-40649
    26Наблюдать

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    softwareag · connx14 июн. 2022 г.

  • CVE-2021-40650
    26Наблюдать

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    softwareag · connx14 июн. 2022 г.

  • CVE-2023-6578
    26Наблюдать

    Software AG WebMethods access control

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    softwareag · webmethods7 дек. 2023 г.

  • CVE-2025-66838
    26Наблюдать

    In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upl

    СредняяCVSS 6,5Proof of conceptEPSS 0 %

    softwareag · aris7 янв. 2026 г.