Attachmate develops Reflection, a suite of terminal-emulation and file-transfer client products deployed across enterprise environments for legacy-system connectivity. Vulnerabilities affecting this vendor cluster around input handling and code generation, with recurrent path-traversal, buffer-boundary, code-injection, and cross-site scripting weaknesses that reflect the web and file-parsing demands of the client application; these disclosures show a moderate tendency toward public exploit availability. Defenders should monitor updates for Reflection deployments, particularly where client systems interact with untrusted file sources or legacy protocols; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Attachmate over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5012HIGH Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2 | Dec 25, 2011 | 10.0 | 44 | NO | YES |
CVE-2014-0605HIGH Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspe | Feb 6, 2015 | 10.0 | 27 | NO | NO |
CVE-2014-0604HIGH Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspe | Feb 6, 2015 | 10.0 | 27 | NO | NO |
CVE-2014-0603HIGH The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary c | Feb 6, 2015 | 10.0 | 26 | NO | NO |
CVE-2014-5211MEDIUM Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response. | Jan 27, 2015 | 6.8 | 25 | NO | NO |
CVE-2014-0607HIGH Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and lau | Jul 24, 2014 | 10.0 | 25 | NO | NO |
CVE-2008-6021HIGH Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and attack vectors, aka "security vulnerabilit | Feb 2, 2009 | 10.0 | 25 | NO | NO |
CVE-2013-3626HIGH Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbit | Nov 6, 2013 | 9.3 | 24 | NO | NO |
CVE-2011-5157MEDIUM Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a relate | Sep 6, 2012 | 6.9 | 21 | NO | NO |
CVE-2010-4146MEDIUM Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject | Nov 2, 2010 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Attachmate.
Media articles that mention a CVE ID that affects a product developed by Attachmate — matched by CVE ID, not by vendor name.