arcinformatique CVE 脆弱性と CVE 一覧(10)

製品(CPE): — CVE 件数: 10

arcinformatique 脆弱性概要

arcinformatique 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには vendor risk cross-site scripting があり、vendor surface production workloads and vendor surface software deployment の利用場面で vendor impact session compromise などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 110 / 10 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-1698 A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout of the WebClient and WebScheduler web apps. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.05% 2026-02-26 2026-03-12
CVE-2026-1697 The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.03% 2026-02-26 2026-03-12
CVE-2026-1696 Some HTTP security headers are not properly set by the web server when sending responses to the client application. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 2.3 0.03% 2026-02-26 2026-03-12
CVE-2026-1695 An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id). This vulnerability only affects the error page of the OAuth server. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.05% 2026-02-26 2026-03-12
CVE-2026-1694 HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 2.3 0.03% 2026-02-26 2026-03-12
CVE-2026-1693 The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.05% 2026-02-26 2026-03-12
CVE-2026-1692 A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website. This vulnerability only affects the following two endpoints: GraphicalData/js/signalR/connect and GraphicalData/js/signalR/reconnect. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.02% 2026-02-26 2026-03-12
CVE-2022-4312 A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email account and SIM card. [email protected] 5.5 0.05% 2022-12-12 2024-11-21
CVE-2022-4311 An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources. [email protected] 4.7 0.36% 2022-12-12 2024-11-21
CVE-2022-2569 The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users [email protected] 5.5 0.05% 2022-08-24 2024-11-21
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence