Known Vulnerabilities for products from Knime
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Knime".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-5562 json | An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When KNIME... | 6.1 - MEDIUM | 2023-10-12 | 2023-10-18 |
| CVE-2023-3140 json | Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulnerable... | 4.3 - MEDIUM | 2023-06-07 | 2023-06-16 |
| CVE-2023-2541 json | The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about the a... | 5.3 - MEDIUM | 2023-06-07 | 2024-01-09 |
| CVE-2022-44749 json | A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can re... | 7 - HIGH | 2022-11-24 | 2023-11-07 |
| CVE-2022-44748 json | A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrar... | 7.5 - HIGH | 2022-11-24 | 2023-11-07 |
| CVE-2022-31500 json | In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions. | 7.8 - HIGH | 2022-06-02 | 2022-11-04 |
| CVE-2021-45097 json | KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in... | 5.5 - MEDIUM | 2021-12-16 | 2023-09-28 |
| CVE-2021-45096 json | KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf... | 4.3 - MEDIUM | 2021-12-16 | 2023-09-28 |
| CVE-2021-44726 json | KNIME Server before 4.13.4 allows XSS via the old WebPortal login page. | 6.1 - MEDIUM | 2021-12-08 | 2023-09-28 |
| CVE-2021-44725 json | KNIME Server before 4.13.4 allows directory traversal in a request for a client profile. | 7.5 - HIGH | 2021-12-08 | 2023-09-28 |