netmotionsoftware CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

netmotionsoftware vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to netmotionsoftware, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-40067 The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14. [email protected] 6.8 0.16% 2021-09-16 2024-11-21
CVE-2021-40066 The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14. [email protected] 5.3 0.16% 2021-09-16 2024-11-21
CVE-2021-26915 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet. [email protected] 8.1 34.16% 2021-02-08 2024-11-21
CVE-2021-26914 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject. [email protected] 8.1 64.44% 2021-02-08 2024-11-21
CVE-2021-26913 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet. [email protected] 8.1 35.43% 2021-02-08 2024-11-21
CVE-2021-26912 NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet. [email protected] 8.1 35.43% 2021-02-08 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence