Determine develops contract lifecycle management software, a function that processes and manages contractual documents and data across enterprise procurement and legal workflows. The vulnerability profile reflects typical application-layer concerns around dynamic code generation, input handling, and XML processing, centered on code injection, cross-site scripting, and XML external entity reference flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Determine over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20155HIGH An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generatin | Jan 5, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-20154MEDIUM An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripting (XSS) vulnerability in multiple getchart.jsp parameters a | Jan 5, 2020 | 6.1 | 21 | NO | NO |
CVE-2019-20153MEDIUM An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature i | Jan 5, 2020 | 4.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Determine.
Media articles that mention a CVE ID that affects a product developed by Determine — matched by CVE ID, not by vendor name.