Bstek develops the uRule business-rules and workflow engine, a narrowly scoped integration component used in enterprise application platforms. The documented vulnerability profile centers on improper handling of XML external entity references, a parsing-layer weakness that reflects the product's XML-driven configuration and data-exchange architecture. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bstek over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24189CRITICAL An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile. | Feb 24, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bstek.
Media articles that mention a CVE ID that affects a product developed by Bstek — matched by CVE ID, not by vendor name.