Cherwell develops a focused service-management platform that handles incident tracking, asset management, and workflow automation for enterprise IT operations. Its observed vulnerability profile centers on web-application input-handling and data-protection issues, including open redirects, cross-site scripting, and missing encryption of sensitive data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cherwell over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26158MEDIUM An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. | Feb 28, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-26156MEDIUM An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request bo | Feb 28, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-26155MEDIUM An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload in the SAMLResponse parameter of the HTTP request body. | Feb 28, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-26157MEDIUM An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to | Feb 28, 2022 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cherwell.
Media articles that mention a CVE ID that affects a product developed by Cherwell — matched by CVE ID, not by vendor name.