Businessdnasolutions has a concentrated vulnerability footprint centered on its TopEase product, a web-facing application that handles authentication and resource access. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the recurrent weakness classes—including improper input validation, cross-site scripting, access-control flaws, and authentication-bypass patterns—are characteristic of web applications managing sensitive user and resource boundaries. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Businessdnasolutions over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42544CRITICAL Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker | Nov 30, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-42115CRITICAL Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privi | Nov 30, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-42545CRITICAL An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or ste | Nov 30, 2021 | 9.1 | 27 | NO | NO |
CVE-2021-42123HIGH Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated rem | Nov 30, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-42120MEDIUM Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated re | Nov 30, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-42119MEDIUM Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Search Functionality allows authenticated | Nov 30, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42118MEDIUM Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Structure Component allows an authenticat | Nov 30, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42117MEDIUM Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker with Object | Nov 30, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42116MEDIUM Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shap | Nov 30, 2021 | 4.3 | 18 | NO | NO |
CVE-2021-42122MEDIUM Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s attributes with numeric format allow | Nov 30, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Businessdnasolutions.
Media articles that mention a CVE ID that affects a product developed by Businessdnasolutions — matched by CVE ID, not by vendor name.