İçeriğe atla
Noroxi

softwareag kayıtları

softwareag üreticisine ait 13 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%7,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

13 kayıt
  • CVE-2019-13990
    44Planlayın

    initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descript

    KritikCVSS 9,8Kavram kanıtıEPSS %16

    softwareag · quartz26 Tem 2019

  • CVE-2020-35469
    40Planlayın

    The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.

    KritikCVSS 9,8İstismar yokEPSS %2

    softwareag · terracotta server oss15 Ara 2020

  • CVE-2021-33207
    39İzleyin

    The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.

    KritikCVSS 9,8İstismar yokEPSS %2

    softwareag · mashzone nextgen4 Nis 2022

  • CVE-2023-39017
    39İzleyin

    quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessag

    KritikCVSS 9,8İstismar yokEPSS %1

    softwareag · quartz28 Tem 2023

  • CVE-2023-0925
    39İzleyin

    Software AG webMethods OneData Deserialization Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    softwareag · webmethods6 Eyl 2023

  • CVE-2021-33523
    29İzleyin

    MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can

    YüksekCVSS 7,2İstismar yokEPSS %2

    softwareag · mashzone nextgen30 Mar 2022

  • CVE-2021-33581
    28İzleyin

    MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the f

    YüksekCVSS 7,2İstismar yokEPSS %1

    softwareag · mashzone nextgen30 Mar 2022

  • CVE-2021-33208
    28İzleyin

    The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML config

    YüksekCVSS 7,2İstismar yokEPSS %1

    softwareag · mashzone nextgen30 Mar 2022

  • CVE-2025-66837
    27İzleyin

    A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

    OrtaCVSS 6,8Kavram kanıtıEPSS %0

    softwareag · aris7 Oca 2026

  • CVE-2021-40649
    26İzleyin

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

    OrtaCVSS 6,5İstismar yokEPSS %1

    softwareag · connx14 Haz 2022

  • CVE-2021-40650
    26İzleyin

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

    OrtaCVSS 6,5İstismar yokEPSS %1

    softwareag · connx14 Haz 2022

  • CVE-2023-6578
    26İzleyin

    Software AG WebMethods access control

    OrtaCVSS 6,5İstismar yokEPSS %1

    softwareag · webmethods7 Ara 2023

  • CVE-2025-66838
    26İzleyin

    In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upl

    OrtaCVSS 6,5Kavram kanıtıEPSS %0

    softwareag · aris7 Oca 2026