MulesoftCVEs & Vulnerabilities

6 CVEs affecting Mulesoft products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

mule runtime 4api gateway 2aplkit 1mule enterprise management console 1
CVE-2020-6937HIGH

A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.

30 May 2020
7.5
CVSS
CVE-2020-10991CRITICAL

Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

27 Mar 2020
9.8
CVSS
CVE-2019-15631CRITICAL

Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

2 Dec 2019
9.8
CVSS
CVE-2019-13116CRITICAL

The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections

16 Oct 2019
9.8
CVSS
CVE-2019-15630HIGH

Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.

30 Aug 2019
7.5
CVSS
CVE-2014-9000MEDIUMpoc

Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.

20 Nov 2014
6.5
CVSS
← PrevPage 1 / 1Next →