Products

Showing 5 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
bonitasoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Bonitasoft Runtime Community edition's contains an insecure direct object references vulnerability

In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.

CWE-284CWE-639May 15, 2024
CVSS6.5v3.1EPSS0.318%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload to the Groups Display name field.

CWE-79Feb 27, 2024
CVSS6.1v3.1EPSS0.527%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

bonitasoft bonita-connector-webservice SecureWSConnector.java TransformerConfigurationException xml external entity reference

A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The patch is named a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associate

CWE-611Jan 5, 2023
CVSS5.5v3.1EPSS0.764%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Bonita Web RestAPIAuthorizationFilter Authentication Bypass Vulnerability

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

CWE-863May 27, 20221 related artifact
CVSS9.8v3.1EPSS56.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

bonitasoft bonita_bpm_portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

CWE-22Jun 18, 20151 related artifact
CVSS5.0v2.0EPSS17.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX