Datev's vulnerability footprint is concentrated in a narrow portfolio of German business and tax software platforms, including its base system and personal management products, with the observed exposure centered on web-application input-handling weaknesses such as cross-site scripting and improper path validation. These vulnerabilities reflect the internet-facing and data-handling role of tax and payroll processing software; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datev over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0689HIGH The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary | Feb 26, 2010 | 10.0 | 28 | NO | NO |
CVE-2011-5158HIGH Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via | Sep 7, 2012 | 9.3 | 27 | NO | NO |
CVE-2003-1169MEDIUM DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values i | Dec 31, 2003 | 4.6 | 21 | NO | YES |
CVE-2023-33387MEDIUM A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' log | Jun 22, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datev.
Media articles that mention a CVE ID that affects a product developed by Datev — matched by CVE ID, not by vendor name.