Instana develops a dynamic application performance monitoring platform that provides visibility and instrumentation across containerized and microservices environments. The disclosed vulnerabilities center on authentication gaps in critical administrative functions, a structural concern for a monitoring tool that holds broad observability access to production systems. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Instana over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35463CRITICAL Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may | Dec 15, 2020 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Instana.
Media articles that mention a CVE ID that affects a product developed by Instana — matched by CVE ID, not by vendor name.