Talend kayıtları
talend üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %5,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-611 Improper Restriction of XML External Entity Reference7
- CWE-306 Missing Authentication for Critical Function2
- CWE-287 Improper Authentication1
- CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2014-2228İstismar yok | The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML mtalend · restlet · CWE-776 | Kritik9,8 | — | %3,3 | 19 Şub 2020 |
39İzleyin | CVE-2021-42837İstismar yok | An issue was discovered in Talend Data Catalog before 7.3-20210930.talend · data catalog · CWE-287 | Kritik9,8 | — | %1,2 | 5 Kas 2021 |
39İzleyin | CVE-2021-4311İstismar yok | Talend Open Studio for MDM XML xml external entity referencetalend · open studio · CWE-611 | Kritik9,8 | — | %0,7 | 9 Oca 2023 |
36İzleyin | CVE-2021-40684İstismar yok | Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint talend · esb runtime | Kritik9,1 | — | %1,2 | 22 Eyl 2021 |
31İzleyin | CVE-2012-2656İstismar yok | An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitivtalend · restlet · CWE-611 | Yüksek7,5 | — | %2,0 | 18 Ara 2019 |
31İzleyin | CVE-2022-45588İstismar yok | All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks.talend · remote engine gen 2 · CWE-611 | Yüksek7,8 | — | %0,2 | 3 Şub 2023 |
30İzleyin | CVE-2023-36301İstismar yok | Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.talend · data catalog · CWE-22 | Yüksek7,5 | — | %0,9 | 26 Haz 2023 |
30İzleyin | CVE-2023-31444İstismar yok | In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of talend · studio · CWE-306 | Yüksek7,5 | — | %0,5 | 28 Nis 2023 |
30İzleyin | CVE-2023-33247İstismar yok | Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be talend · data catalog · CWE-306 | Yüksek7,5 | — | %0,5 | 26 May 2023 |
28İzleyin | CVE-2022-45589İstismar yok | All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks intalend · esb runtime · CWE-89 | Yüksek7,2 | — | %0,6 | 6 Şub 2023 |
26İzleyin | CVE-2022-29943İstismar yok | Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve retalend · administration center · CWE-611 | Orta6,5 | — | %0,9 | 4 May 2022 |
26İzleyin | CVE-2022-29942İstismar yok | Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perfortalend · administration center · CWE-918 | Orta6,5 | — | %0,7 | 4 May 2022 |
24İzleyin | CVE-2022-31648İstismar yok | Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint.talend · administration center · CWE-79 | Orta6,1 | — | %0,6 | 26 May 2022 |
22İzleyin | CVE-2023-26263İstismar yok | All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServitalend · data catalog · CWE-611 | Orta5,5 | — | %0,2 | 13 Nis 2023 |
22İzleyin | CVE-2023-26264İstismar yok | All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsitalend · data catalog · CWE-611 | Orta5,5 | — | %0,2 | 13 Nis 2023 |
21İzleyin | CVE-2022-30332İstismar yok | In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid rtalend · administration center · CWE-203 | Orta5,3 | — | %0,8 | 10 Oca 2023 |
17İzleyin | CVE-2022-4818İstismar yok | Talend Open Studio for MDM SystemStorageWrapper.java xml external entity referencetalend · open studio for mdm · CWE-611 | Orta4,3 | — | %0,5 | 28 Ara 2022 |
- CVE-2014-222840Planlayın
The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML m
KritikCVSS 9,8İstismar yokEPSS %3talend · restlet19 Şub 2020
- CVE-2021-4283739İzleyin
An issue was discovered in Talend Data Catalog before 7.3-20210930.
KritikCVSS 9,8İstismar yokEPSS %1talend · data catalog5 Kas 2021
- CVE-2021-431139İzleyin
Talend Open Studio for MDM XML xml external entity reference
KritikCVSS 9,8İstismar yokEPSS %1talend · open studio9 Oca 2023
- CVE-2021-4068436İzleyin
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint
KritikCVSS 9,1İstismar yokEPSS %1talend · esb runtime22 Eyl 2021
- CVE-2012-265631İzleyin
An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitiv
YüksekCVSS 7,5İstismar yokEPSS %2talend · restlet18 Ara 2019
- CVE-2022-4558831İzleyin
All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks.
YüksekCVSS 7,8İstismar yokEPSS %0talend · remote engine gen 23 Şub 2023
- CVE-2023-3630130İzleyin
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
YüksekCVSS 7,5İstismar yokEPSS %1talend · data catalog26 Haz 2023
- CVE-2023-3144430İzleyin
In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of
YüksekCVSS 7,5İstismar yokEPSS %1talend · studio28 Nis 2023
- CVE-2023-3324730İzleyin
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be
YüksekCVSS 7,5İstismar yokEPSS %0talend · data catalog26 May 2023
- CVE-2022-4558928İzleyin
All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in
YüksekCVSS 7,2İstismar yokEPSS %1talend · esb runtime6 Şub 2023
- CVE-2022-2994326İzleyin
Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve re
OrtaCVSS 6,5İstismar yokEPSS %1talend · administration center4 May 2022
- CVE-2022-2994226İzleyin
Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perfor
OrtaCVSS 6,5İstismar yokEPSS %1talend · administration center4 May 2022
- CVE-2022-3164824İzleyin
Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint.
OrtaCVSS 6,1İstismar yokEPSS %1talend · administration center26 May 2022
- CVE-2023-2626322İzleyin
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServi
OrtaCVSS 5,5İstismar yokEPSS %0talend · data catalog13 Nis 2023
- CVE-2023-2626422İzleyin
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsi
OrtaCVSS 5,5İstismar yokEPSS %0talend · data catalog13 Nis 2023
- CVE-2022-3033221İzleyin
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid r
OrtaCVSS 5,3İstismar yokEPSS %1talend · administration center10 Oca 2023
- CVE-2022-481817İzleyin
Talend Open Studio for MDM SystemStorageWrapper.java xml external entity reference
OrtaCVSS 4,3İstismar yokEPSS %1talend · open studio for mdm28 Ara 2022