Graniteds develops data-integration and data-services middleware that processes structured data flows, with its vulnerability footprint centered on deserialization of untrusted data and improper control of dynamically-managed code resources—weaknesses characteristic of systems that consume and execute serialized or runtime-generated content. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graniteds over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-3200HIGH The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subse | Jun 11, 2018 | 8.1 | 22 | NO | NO |
CVE-2017-3199HIGH The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation o | Jun 11, 2018 | 8.1 | 22 | NO | NO |
CVE-2016-2340MEDIUM The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of ser | Mar 25, 2016 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graniteds.
Media articles that mention a CVE ID that affects a product developed by Graniteds — matched by CVE ID, not by vendor name.