Business Dnasolutions develops a narrowly scoped product portfolio centered on its Topease offering, which has surfaced a minimal vulnerability disclosure record. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Business Dnasolutions over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42544CRITICAL Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker | Nov 30, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-42115CRITICAL Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privi | Nov 30, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-42545CRITICAL An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or ste | Nov 30, 2021 | 9.1 | 27 | NO | NO |
CVE-2021-42123HIGH Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated rem | Nov 30, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-42120MEDIUM Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated re | Nov 30, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-42119MEDIUM Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Search Functionality allows authenticated | Nov 30, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42118MEDIUM Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Structure Component allows an authenticat | Nov 30, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42117MEDIUM Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker with Object | Nov 30, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42116MEDIUM Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shap | Nov 30, 2021 | 4.3 | 18 | NO | NO |
CVE-2021-42122MEDIUM Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s attributes with numeric format allow | Nov 30, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Business Dnasolutions.
Media articles that mention a CVE ID that affects a product developed by Business Dnasolutions — matched by CVE ID, not by vendor name.