Known Vulnerabilities for products from Primekey

Listed below are 15 of the newest known vulnerabilities associated with the vendor "Primekey".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-40711 json PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can injec... 4.8 - MEDIUM 2023-01-01 2023-01-09
CVE-2022-34831 json An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers subm... 9.8 - CRITICAL 2022-09-14 2022-09-16
CVE-2022-26494 json An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worke... 4.8 - MEDIUM 2022-03-21 2022-03-28
CVE-2021-40089 json An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke... 2.3 - LOW 2021-08-25 2021-09-09
CVE-2021-40088 json An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to au... 5.4 - MEDIUM 2021-08-25 2021-09-07
CVE-2021-40087 json An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various pro... 2.7 - LOW 2021-08-25 2021-09-07
CVE-2021-40086 json An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and A... 2.2 - LOW 2021-08-25 2022-07-12
CVE-2020-28942 json An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. A... 4.3 - MEDIUM 2020-11-19 2020-12-03
CVE-2020-25276 json An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST pr... 7.3 - HIGH 2020-09-11 2020-09-16
CVE-2020-11631 json An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a ma... 6.5 - MEDIUM 2020-04-08 2021-07-21
CVE-2020-11630 json An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of ser... 9.8 - CRITICAL 2020-04-08 2020-04-08
CVE-2020-11629 json An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which al... 7.2 - HIGH 2020-04-08 2021-07-21
CVE-2020-11628 json An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available r... 5.3 - MEDIUM 2020-04-08 2020-04-08
CVE-2020-11627 json An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been f... 8.8 - HIGH 2020-04-08 2020-04-08
CVE-2020-11626 json An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have ... 6.1 - MEDIUM 2020-04-08 2020-04-08

Known software with vulnerabilities from Primekey

Type Vendor Product Version
ApplicationPrimekeyEjbca6.15.2.6

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report