Hawt develops Hawtio, a web-based management console for monitoring and administering Java applications and middleware, with its vulnerability profile skewing strongly toward critical-severity outcomes across a narrowly scoped product line. The recurring weakness classes center on web-application-layer flaws including cross-site request forgery, path traversal, improper authentication and authorization, and sensitive information exposure in error messages—attack vectors characteristic of internet-exposed management interfaces. Defenders should treat Hawt advisories as high-priority for any exposed or internally accessible instances; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hawt over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9827CRITICAL Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substrin | Jul 3, 2019 | 9.8 | 37 | NO | NO |
CVE-2014-0121CRITICAL The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. | Dec 29, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-2589CRITICAL It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed betw | Jul 26, 2018 | 9.0 | 28 | NO | NO |
CVE-2017-2617HIGH hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a t | May 22, 2018 | 7.8 | 26 | NO | NO |
CVE-2017-7556HIGH Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script whic | Aug 17, 2017 | 8.8 | 26 | NO | NO |
CVE-2014-0120HIGH Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run comma | Dec 29, 2017 | 8.8 | 23 | NO | NO |
CVE-2017-2594HIGH hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An atta | May 8, 2018 | 7.5 | 21 | NO | NO |
CVE-2023-33544MEDIUM hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location | Jun 1, 2023 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hawt.
Media articles that mention a CVE ID that affects a product developed by Hawt — matched by CVE ID, not by vendor name.