SoftvibeCVEs & Vulnerabilities
4 CVEs affecting Softvibe products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
saraban 4
CVE-2021-38697CRITICAL
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
18 Jan 2022
9.8
CVSS
CVE-2021-38696HIGH
SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.
18 Jan 2022
7.5
CVSS
CVE-2021-38695MEDIUM
SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in certain fields (e.g. subject, description) of the document form.
18 Jan 2022
5.4
CVSS
CVE-2021-38694HIGH
SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
18 Jan 2022
7.5
CVSS
← PrevPage 1 / 1Next →