Known Vulnerabilities for Metasys Extended Application And Data Server by Johnsoncontrols
Listed below are 10 of the newest known vulnerabilities associated with "Metasys Extended Application And Data Server" by "Johnsoncontrols".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-21938 json | Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 ve... | 5.4 - MEDIUM | 2022-06-15 | 2022-06-24 |
| CVE-2022-21937 json | Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 ve... | 5.4 - MEDIUM | 2022-06-15 | 2022-06-24 |
| CVE-2022-21936 json | On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a ... | 6.5 - MEDIUM | 2022-10-07 | 2023-11-07 |
| CVE-2022-21935 json | A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows... | 7.5 - HIGH | 2022-06-15 | 2022-06-24 |
| CVE-2022-21934 json | Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Met... | 8.8 - HIGH | 2022-05-06 | 2022-05-16 |
| CVE-2021-36207 json | Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an au... | 8.8 - HIGH | 2022-04-29 | 2022-05-11 |
| CVE-2021-36205 json | Under certain circumstances the session token is not cleared on logout. | 9.8 - CRITICAL | 2022-04-15 | 2022-04-25 |
| CVE-2021-36204 json | Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 ver... | 7.5 - HIGH | 2023-01-13 | 2023-01-23 |
| CVE-2021-36202 json | Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject ... | 8.8 - HIGH | 2022-04-07 | 2022-04-14 |
| CVE-2021-36200 json | Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to... | 5.3 - MEDIUM | 2022-07-22 | 2022-07-29 |