Archibus operates a niche enterprise facilities-management and workplace platform, with its vulnerability footprint centered on the Web Central application that serves as the core interface for this workflow. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in access-control, SQL injection, cross-site scripting, and information-disclosure weaknesses that are characteristic of web-facing enterprise applications handling sensitive facility and occupancy data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Archibus over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28862CRITICAL In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL stateme | May 25, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-41553CRITICAL In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was th | Oct 5, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-45165HIGH An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It cau | Jan 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-41554HIGH ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edit | Oct 5, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-41555MEDIUM In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflowRule.dwr because the data received as input from clients is | Oct 5, 2021 | 6.1 | 20 | NO | NO |
CVE-2022-45167MEDIUM An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to access the profile information of all connected users. | Jan 10, 2023 | 4.3 | 18 | NO | NO |
CVE-2022-45166MEDIUM An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data re | Jan 10, 2023 | 4.3 | 18 | NO | NO |
CVE-2022-45164MEDIUM An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to cancel (delete) a booking, created by someone else - eve | Jan 10, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Archibus.
Media articles that mention a CVE ID that affects a product developed by Archibus — matched by CVE ID, not by vendor name.