Known Vulnerabilities for products from Tufin
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Tufin".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-13462 json | Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in vers... | 5.7 - MEDIUM | 2021-02-09 | 2021-07-21 |
| CVE-2020-13461 json | Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not ... | 4.3 - MEDIUM | 2021-02-09 | 2021-02-12 |
| CVE-2020-13460 json | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to... | 8.8 - HIGH | 2021-02-09 | 2021-05-11 |
| CVE-2020-13409 json | Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also sto... | 5.9 - MEDIUM | 2021-02-09 | 2021-03-08 |
| CVE-2020-13408 json | Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also sto... | 5.9 - MEDIUM | 2021-02-09 | 2021-03-08 |
| CVE-2020-13407 json | Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also sto... | 5.9 - MEDIUM | 2021-02-09 | 2021-03-08 |
| CVE-2020-13134 json | Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin ... | 4.8 - MEDIUM | 2021-01-20 | 2021-01-23 |
| CVE-2020-13133 json | Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin ... | 6.1 - MEDIUM | 2021-01-20 | 2021-01-23 |
| CVE-2018-18406 json | An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by... | 9.9 - CRITICAL | 2019-06-19 | 2019-06-24 |
Known software with vulnerabilities from Tufin
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Tufin | Securechange | r17-3 |
| Application | Tufin | Securetrack | - |
| Operating System | Tufin | Tufinos | 2.16 |