softwareag kayıtları
softwareag üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %7,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2019-13990Kavram kanıtı | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descriptsoftwareag · quartz · CWE-611 | Kritik9,8 | — | %16,2 | 26 Tem 2019 |
40Planlayın | CVE-2020-35469İstismar yok | The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.softwareag · terracotta server oss · CWE-306 | Kritik9,8 | — | %2,1 | 15 Ara 2020 |
39İzleyin | CVE-2021-33207İstismar yok | The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.softwareag · mashzone nextgen · CWE-502 | Kritik9,8 | — | %1,6 | 4 Nis 2022 |
39İzleyin | CVE-2023-39017İstismar yok | quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessagsoftwareag · quartz · CWE-94 | Kritik9,8 | — | %1,2 | 28 Tem 2023 |
39İzleyin | CVE-2023-0925İstismar yok | Software AG webMethods OneData Deserialization Vulnerabilitysoftwareag · webmethods · CWE-502 | Kritik9,8 | — | %0,8 | 6 Eyl 2023 |
29İzleyin | CVE-2021-33523İstismar yok | MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can softwareag · mashzone nextgen | Yüksek7,2 | — | %1,8 | 30 Mar 2022 |
28İzleyin | CVE-2021-33581İstismar yok | MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the fsoftwareag · mashzone nextgen · CWE-918 | Yüksek7,2 | — | %1,3 | 30 Mar 2022 |
28İzleyin | CVE-2021-33208İstismar yok | The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configsoftwareag · mashzone nextgen · CWE-611 | Yüksek7,2 | — | %1,2 | 30 Mar 2022 |
27İzleyin | CVE-2025-66837Kavram kanıtı | A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malwaresoftwareag · aris · CWE-434 | Orta6,8 | — | %0,3 | 7 Oca 2026 |
26İzleyin | CVE-2021-40649İstismar yok | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.softwareag · connx · CWE-732 | Orta6,5 | — | %0,8 | 14 Haz 2022 |
26İzleyin | CVE-2021-40650İstismar yok | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.softwareag · connx · CWE-311 | Orta6,5 | — | %0,8 | 14 Haz 2022 |
26İzleyin | CVE-2023-6578İstismar yok | Software AG WebMethods access controlsoftwareag · webmethods · CWE-284 | Orta6,5 | — | %0,7 | 7 Ara 2023 |
26İzleyin | CVE-2025-66838Kavram kanıtı | In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to uplsoftwareag · aris · CWE-770 | Orta6,5 | — | %0,4 | 7 Oca 2026 |
- CVE-2019-1399044Planlayın
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job descript
KritikCVSS 9,8Kavram kanıtıEPSS %16softwareag · quartz26 Tem 2019
- CVE-2020-3546940Planlayın
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.
KritikCVSS 9,8İstismar yokEPSS %2softwareag · terracotta server oss15 Ara 2020
- CVE-2021-3320739İzleyin
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
KritikCVSS 9,8İstismar yokEPSS %2softwareag · mashzone nextgen4 Nis 2022
- CVE-2023-3901739İzleyin
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessag
KritikCVSS 9,8İstismar yokEPSS %1softwareag · quartz28 Tem 2023
- CVE-2023-092539İzleyin
Software AG webMethods OneData Deserialization Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1softwareag · webmethods6 Eyl 2023
- CVE-2021-3352329İzleyin
MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can
YüksekCVSS 7,2İstismar yokEPSS %2softwareag · mashzone nextgen30 Mar 2022
- CVE-2021-3358128İzleyin
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the f
YüksekCVSS 7,2İstismar yokEPSS %1softwareag · mashzone nextgen30 Mar 2022
- CVE-2021-3320828İzleyin
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML config
YüksekCVSS 7,2İstismar yokEPSS %1softwareag · mashzone nextgen30 Mar 2022
- CVE-2025-6683727İzleyin
A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware
OrtaCVSS 6,8Kavram kanıtıEPSS %0softwareag · aris7 Oca 2026
- CVE-2021-4064926İzleyin
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
OrtaCVSS 6,5İstismar yokEPSS %1softwareag · connx14 Haz 2022
- CVE-2021-4065026İzleyin
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
OrtaCVSS 6,5İstismar yokEPSS %1softwareag · connx14 Haz 2022
- CVE-2023-657826İzleyin
Software AG WebMethods access control
OrtaCVSS 6,5İstismar yokEPSS %1softwareag · webmethods7 Ara 2023
- CVE-2025-6683826İzleyin
In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upl
OrtaCVSS 6,5Kavram kanıtıEPSS %0softwareag · aris7 Oca 2026