Idera's vulnerability footprint spans a narrow infrastructure-monitoring and business-intelligence product portfolio that holds a prominent position within its operational niches. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring weakness classes including sensitive-information exposure, SQL injection, path traversal, cross-site scripting, and buffer-boundary violations that are characteristic of web-facing and data-access components. Defenders should prioritize patching in environments where Uptime Infrastructure Monitor and Yellowfin Business Intelligence are deployed, particularly internet-exposed instances; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idera over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9263CRITICAL An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file | Aug 27, 2018 | 9.8 | 40 | NO | YES |
CVE-2017-11471CRITICAL IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter. | Jul 20, 2017 | 9.8 | 34 | NO | YES |
CVE-2017-11470CRITICAL IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter. | Jul 20, 2017 | 9.8 | 34 | NO | YES |
CVE-2017-11469HIGH get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter. | Jul 20, 2017 | 7.5 | 30 | NO | YES |
CVE-2015-8268HIGH The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecified vectors. | Jun 10, 2016 | 7.5 | 24 | NO | NO |
CVE-2020-19587MEDIUM Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI. | Sep 14, 2022 | 5.4 | 21 | NO | NO |
CVE-2015-2895HIGH Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via long command input. | Dec 31, 2015 | 7.3 | 19 | NO | NO |
CVE-2015-2896MEDIUM The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a | Dec 31, 2015 | 5.3 | 16 | NO | NO |
CVE-2015-2894MEDIUM Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via fo | Dec 31, 2015 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idera.
Media articles that mention a CVE ID that affects a product developed by Idera — matched by CVE ID, not by vendor name.