horizoncloud CVE Vulnerabilities & CVE List (11)

Products (CPE): — CVEs: 11

horizoncloud vulnerability overview

Aggregates CVE and security vulnerability intelligence across all horizoncloud-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk sql injection; exposure may include vendor impact data exposure in vendor surface production workloads and vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 111 of 11 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-38891 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information. [email protected] 7.5 0.53% 2024-08-02 2026-02-24
CVE-2024-38887 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges. [email protected] 9.8 1.68% 2024-08-02 2024-08-20
CVE-2024-38889 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command. [email protected] 9.8 0.90% 2024-08-02 2026-02-20
CVE-2024-38888 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts. [email protected] 6.8 0.21% 2024-08-02 2025-05-13
CVE-2024-38886 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel. [email protected] 9.8 0.76% 2024-08-02 2026-02-24
CVE-2024-38885 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application. [email protected] 7.5 0.61% 2024-08-02 2025-05-13
CVE-2024-38884 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms [email protected] 7.8 0.20% 2024-08-02 2025-05-13
CVE-2024-38883 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation. [email protected] 9.1 0.41% 2024-08-02 2025-05-13
CVE-2024-38882 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command. [email protected] 9.8 0.96% 2024-08-02 2026-02-24
CVE-2024-38881 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords. [email protected] 7.5 0.53% 2024-08-02 2026-02-24
CVE-2024-38890 An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks. [email protected] 8.4 0.21% 2024-08-02 2025-05-06
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence