Hexagon Geospatial produces a focused set of geospatial and mapping products such as ERDAS ER Viewer and GeoMedia WebMap, which serve specialized GIS and geospatial analysis workflows. Its observed vulnerability footprint centers on application-layer input handling, with recurring issues including SQL injection and uncontrolled search path elements characteristic of web-facing and file-processing components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hexagongeospatial over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37749CRITICAL MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method. | Aug 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2013-0725HIGH ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities | Jan 30, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hexagongeospatial.
Media articles that mention a CVE ID that affects a product developed by Hexagongeospatial — matched by CVE ID, not by vendor name.