Hammock's vulnerability footprint centers on its AssetView product, an asset and IT management application, with observed weaknesses spanning path-traversal flaws, SQL-injection issues, and missing authentication controls for critical functions. These are characteristic input-validation and access-control gaps in web and database-facing management tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hammock over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28719CRITICAL Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a c | Apr 28, 2022 | 9.8 | 25 | NO | NO |
CVE-2017-2240MEDIUM Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service". | Jul 17, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-2241MEDIUM SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service". | Jul 17, 2017 | 6.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hammock.
Media articles that mention a CVE ID that affects a product developed by Hammock — matched by CVE ID, not by vendor name.