Tririga Application Platform

Vendor:

First CVE: Apr 23, 2013 · Active for 13 years

47
Total CVEs
More Total CVEs than 97% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tririga Application Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2013
13 years ago
Most Recent CVE
Jun 22, 2026
33 days ago

CVE Severity & Scoring

Tririga Application Platform47 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local1 (2.1%)
Network33 (70.2%)
Unknown13 (27.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (70.2%)
High1 (2.1%)
Unknown13 (27.7%)
User Interaction
None22 (46.8%)
Unknown13 (27.7%)
Required12 (25.5%)
Privileges Required
Low29 (61.7%)
High0 (0.0%)
None5 (10.6%)
Unknown13 (27.7%)

Top CVEs

Signals from CVEs in this product scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have acce
Jul 21, 20178.828NONO
IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute actions that they do not have access to. IBM Reference #: 1999
Mar 27, 20178.828NONO
The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gai
Nov 30, 20168.828NONO
Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute Builder tool actions they
Jul 21, 20178.827NONO
The builder tools in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allow remote authenticated users to gain privileges for applica
Jul 1, 20168.827NONO
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info
Apr 7, 20237.124NONO
IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an attacker formulate future attacks. IBM X-Force ID: 175993.
Apr 17, 20207.524NONO
IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulne
May 7, 20197.124NONO
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users
Jul 2, 20168.024NONO
IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in th
Jun 22, 20265.423NONO

Exploit Exposure

Signals from CVEs in this product scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (47 CVEs).

Media Mentions

Signals from CVEs in this product scope (47 CVEs).

Top CNAs Publishing CVEs For Tririga Application Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.035.10.9%00
5.0.315.40.2%00
5.0.215.40.2%00
4.017.10.9%00
3.6.1.017.51.4%00
3.5.326.51.0%00
3.5.2.315.40.6%00
3.5.2.257.01.1%00
3.5.2.157.01.1%00
3.5.296.51.0%00
3.5.1.386.71.0%00
3.5.1.286.71.0%00
3.5.1.1106.50.9%00
3.5.1.035.60.7%00
3.5.186.71.0%00
3.5.0.286.71.0%00
3.5.0.1166.50.9%00
3.5.0.0226.10.9%00
3.4.2.596.51.0%00
3.4.2.4116.40.9%00