MuleSoft kayıtları
mulesoft üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-502 Deserialization of Untrusted Data1
- CWE-611 Improper Restriction of XML External Entity Reference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-13116İstismar yok | The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserializatmulesoft · mule runtime · CWE-502 | Kritik9,8 | — | %5,1 | 16 Eki 2019 |
40Planlayın | CVE-2019-15631İstismar yok | Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers mulesoft · api gateway | Kritik9,8 | — | %2,3 | 1 Ara 2019 |
39İzleyin | CVE-2020-10991İstismar yok | Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.javamulesoft · aplkit · CWE-611 | Kritik9,8 | — | %1,4 | 26 Mar 2020 |
31İzleyin | CVE-2019-15630İstismar yok | Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before Augumulesoft · api gateway · CWE-22 | Yüksek7,5 | — | %3,0 | 30 Ağu 2019 |
30İzleyin | CVE-2020-6937İstismar yok | A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers tmulesoft · mule runtime | Yüksek7,5 | — | %1,2 | 29 May 2020 |
29İzleyin | CVE-2014-9000Kavram kanıtı | Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticatedmulesoft · mule enterprise management console · CWE-264 | Orta6,5 | — | %8,9 | 20 Kas 2014 |
- CVE-2019-1311641Planlayın
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserializat
KritikCVSS 9,8İstismar yokEPSS %5mulesoft · mule runtime16 Eki 2019
- CVE-2019-1563140Planlayın
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers
KritikCVSS 9,8İstismar yokEPSS %2mulesoft · api gateway1 Ara 2019
- CVE-2020-1099139İzleyin
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
KritikCVSS 9,8İstismar yokEPSS %1mulesoft · aplkit26 Mar 2020
- CVE-2019-1563031İzleyin
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before Augu
YüksekCVSS 7,5İstismar yokEPSS %3mulesoft · api gateway30 Ağu 2019
- CVE-2020-693730İzleyin
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %1mulesoft · mule runtime29 May 2020
- CVE-2014-900029İzleyin
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated
OrtaCVSS 6,5Kavram kanıtıEPSS %9mulesoft · mule enterprise management console20 Kas 2014