Skip to main content

Vendor archive

redwood CVEs

Beta · best-effort

6 CVEs tagged to vendor redwood0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-4528

Published Sep 7, 2023

Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its m…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-26711

Published Feb 5, 2021

A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/def…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26710

Published Feb 5, 2021

A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2401

Published Mar 14, 2018

SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnera…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2400

Published Mar 14, 2018

Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted.

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-2366

Published Mar 14, 2018

SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1