Apperta develops the OpenEye platform for healthcare data sharing and interoperability, with its vulnerability footprint centered on web-application input handling and information-disclosure weaknesses including cross-site scripting and exposure of sensitive data. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apperta over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40375MEDIUM Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a | Apr 6, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-40374MEDIUM A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web | Apr 6, 2022 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apperta.
Media articles that mention a CVE ID that affects a product developed by Apperta — matched by CVE ID, not by vendor name.