Getahead maintains Direct Web Remoting, a web-communication framework component that supports real-time client-server interaction in Java applications. The vendor's observed vulnerability footprint is narrow and centers on this single product, with characterization limited by the classification of reported weaknesses. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getahead over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0184HIGH Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks. | Jan 12, 2007 | 7.5 | 21 | NO | NO |
CVE-2006-6916HIGH Getahead Direct Web Remoting (DWR) before 1.1.3 allows attackers to cause a denial of service (infinite loop) via unknown vectors related to "crafted input." | Dec 31, 2006 | 7.5 | 20 | NO | NO |
CVE-2007-2377MEDIUM The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers | Apr 30, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-0185MEDIUM Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number o | Jan 12, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getahead.
Media articles that mention a CVE ID that affects a product developed by Getahead — matched by CVE ID, not by vendor name.