Known Vulnerabilities for products from Sysaid
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Sysaid".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-47247 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.3 - MEDIUM | 2023-12-25 | 2024-01-04 |
| CVE-2023-47246 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2023-11-10 | 2023-11-13 |
| CVE-2023-33706 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2023-11-24 | 2023-11-30 |
| CVE-2023-32226 json | Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files from th... | 6.5 - MEDIUM | 2023-07-30 | 2023-08-03 |
| CVE-2023-32225 json | Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may b... | 7.2 - HIGH | 2023-07-30 | 2023-08-03 |
| CVE-2022-40325 json | SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. | 6.1 - MEDIUM | 2022-09-11 | 2022-09-15 |
| CVE-2022-40324 json | SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. | 6.1 - MEDIUM | 2022-09-11 | 2022-09-15 |
| CVE-2022-40323 json | SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. | 6.1 - MEDIUM | 2022-09-11 | 2022-09-14 |
| CVE-2022-40322 json | SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579. | 6.1 - MEDIUM | 2022-09-11 | 2022-09-15 |
| CVE-2022-23170 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-06-24 | 2022-07-07 |
| CVE-2022-23166 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-05-12 | 2022-05-23 |
| CVE-2022-23165 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-05-12 | 2022-05-23 |
| CVE-2022-22798 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2022-05-12 | 2023-08-08 |
| CVE-2022-22797 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-05-12 | 2022-05-23 |
| CVE-2022-22796 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-05-12 | 2022-05-23 |
| CVE-2021-43974 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.3 - MEDIUM | 2022-01-11 | 2022-07-12 |
| CVE-2021-43973 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2022-01-11 | 2022-01-20 |
| CVE-2021-43972 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-01-11 | 2022-01-20 |
| CVE-2021-43971 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2022-01-11 | 2022-01-19 |
| CVE-2021-36721 json | Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version... | 5.3 - MEDIUM | 2021-12-14 | 2022-07-12 |
Known software with vulnerabilities from Sysaid
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Sysaid | On-premise | 20.1.11 |
| Application | Sysaid | Sysaid | 14.4 |
| Application | Sysaid | Sysaid Admin Tools | 6.0 |
| Application | Sysaid | Sysaid On-premises | 14.1 |