Anomali develops threat-intelligence and security-analytics platforms, with its vulnerability footprint centered on products such as Agave and Match that handle data ingestion and threat matching. The durable signal centers on command-injection and insufficient-randomness weaknesses, characteristic of backend processing pipelines that parse untrusted threat feeds and generate security artifacts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anomali over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11641HIGH Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the | May 1, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-49329HIGH Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of untruste | Jan 19, 2024 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anomali.
Media articles that mention a CVE ID that affects a product developed by Anomali — matched by CVE ID, not by vendor name.