Skip to main content

Vendor/product archive

archibus / web_central CVEs

Beta · best-effort

5 CVEs tagged to archibus / web_central2 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-45165

Published Jan 10, 2023

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It ca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28862

Published May 25, 2022

In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statem…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41553

Published Oct 5, 2021

In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41555

Published Oct 5, 2021

In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflowRule.dwr because the data received as input from clients i…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41554

Published Oct 5, 2021

ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1