Altova develops XML and data integration tools including MobileToogether Server, MapForce, and related utilities that process structured data formats at scale. Its vulnerability footprint reflects the attack surface inherent to XML parsing and entity processing, with recurring exposure in XML entity expansion and external entity reference handling, weakness classes that characterize libraries and applications that consume untrusted XML documents. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Altova over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37425CRITICAL Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then r | Aug 10, 2021 | 9.1 | 76 | NO | YES |
CVE-2021-38490HIGH Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425. | Aug 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2010-5273MEDIUM Untrusted search path vulnerability in Altova DiffDog 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working di | Sep 7, 2012 | 6.9 | 21 | NO | NO |
CVE-2010-5272MEDIUM Untrusted search path vulnerability in Altova DatabaseSpy 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current workin | Sep 7, 2012 | 6.9 | 21 | NO | NO |
CVE-2010-5271MEDIUM Untrusted search path vulnerability in Altova MapForce 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working d | Sep 7, 2012 | 6.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Altova.
Media articles that mention a CVE ID that affects a product developed by Altova — matched by CVE ID, not by vendor name.