Halvotec's vulnerability profile centers on its raquest product, a web-facing application where exposure recurs through input-handling and session-management weaknesses including cross-site scripting, injection flaws, session fixation, and open-redirect issues. These weakness classes are characteristic of web application architecture and reflect the validation and encoding demands of user-supplied and dynamically generated content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Halvotec over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19614HIGH An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identi | Mar 9, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-19611HIGH An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to access the list of connected users as well as the session coo | Mar 13, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-19612MEDIUM An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site Scripting (XSS). Fixed in Release 24.2020.20608.0. | Mar 16, 2020 | 5.4 | 20 | NO | NO |
CVE-2019-19613MEDIUM An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user | Mar 16, 2020 | 5.2 | 19 | NO | NO |
CVE-2019-19610MEDIUM An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0. | Mar 16, 2020 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Halvotec.
Media articles that mention a CVE ID that affects a product developed by Halvotec — matched by CVE ID, not by vendor name.