Aternity's vulnerability profile centers on its application performance monitoring and user-experience management platform, with the durable signal reflecting common web application and privilege-handling issues such as cross-site scripting, improper privilege management, and resource-transfer weaknesses. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aternity over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5062CRITICAL The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by | Sep 29, 2016 | 9.8 | 31 | NO | NO |
CVE-2022-43997HIGH Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficiently protected handle to the A180AG.ex | Jan 26, 2023 | 7.8 | 24 | NO | NO |
CVE-2016-5061MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTPAgent, | Sep 29, 2016 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aternity.
Media articles that mention a CVE ID that affects a product developed by Aternity — matched by CVE ID, not by vendor name.