netmotionsoftware CVE 脆弱性と CVE 一覧(6)

製品(CPE): — CVE 件数: 6

netmotionsoftware 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to netmotionsoftware, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 16 / 6 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2021-40067 The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14. [email protected] 6.8 0.56% 2021-09-16 2026-06-17
CVE-2021-40066 The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14. [email protected] 5.3 0.56% 2021-09-16 2026-06-17
CVE-2021-26915 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet. [email protected] 8.1 41.84% 2021-02-08 2026-06-16
CVE-2021-26914 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject. [email protected] 8.1 77.67% 2021-02-08 2026-06-16
CVE-2021-26913 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet. [email protected] 8.1 13.28% 2021-02-08 2026-06-16
CVE-2021-26912 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet. [email protected] 8.1 41.05% 2021-02-08 2026-06-16
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence