Known Vulnerabilities for Metasys Open Application Server by Johnsoncontrols
Listed below are 10 of the newest known vulnerabilities associated with "Metasys Open Application Server" by "Johnsoncontrols".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-21938 | Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 ve... | 5.4 - MEDIUM | 2022-06-15 | 2022-06-24 |
| CVE-2022-21937 | Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 ve... | 5.4 - MEDIUM | 2022-06-15 | 2022-06-24 |
| CVE-2022-21935 | A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows... | 7.5 - HIGH | 2022-06-15 | 2022-06-24 |
| CVE-2022-21934 | Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Met... | 8.8 - HIGH | 2022-05-06 | 2022-05-16 |
| CVE-2021-36207 | Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an au... | 8.8 - HIGH | 2022-04-29 | 2022-05-11 |
| CVE-2021-36205 | Under certain circumstances the session token is not cleared on logout. | 9.8 - CRITICAL | 2022-04-15 | 2022-04-25 |
| CVE-2021-36204 | Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 ver... | 7.5 - HIGH | 2023-01-13 | 2023-01-23 |
| CVE-2021-36202 | Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject ... | 8.8 - HIGH | 2022-04-07 | 2022-04-14 |
| CVE-2021-36200 | Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to... | 5.3 - MEDIUM | 2022-07-22 | 2022-07-29 |
| CVE-2020-9044 | XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or h... | 9.1 - CRITICAL | 2020-03-10 | 2020-03-11 |