Known Vulnerabilities for products from Bonitasoft
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Bonitasoft".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-25237 json | Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern u... | 9.8 - CRITICAL | 2022-06-02 | 2023-08-08 |
| CVE-2020-36640 json | A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This a... | 9.8 - CRITICAL | 2023-01-05 | 2023-11-16 |
| CVE-2015-3898 json | Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrar... | 6.1 - MEDIUM | 2018-02-28 | 2019-04-30 |
| CVE-2015-3897 json | Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. ... | Not Provided | 2015-06-18 | 2026-05-06 |
Known software with vulnerabilities from Bonitasoft
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Bonitasoft | Bonita Bpm Portal | 5.10 |