Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Intersystems

First CVE: Aug 7, 2003Active for: 23 yearsTotal CVEs: 10
24.4
VTI Score
Low

Intersystems operates a narrowly focused product portfolio centered on the Cache database platform, which serves as a persistence and integration layer in healthcare, financial, and enterprise data environments. The vendor's vulnerability footprint concentrates around access-control weaknesses, code-injection flaws, and input-handling issues spanning web interfaces and data-query contexts, reflecting the application-facing attack surface of a widely embedded database system. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Intersystems over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2003
22 years ago
Most Recent CVE
Jul 11, 2019
2,570 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2003-0497HIGH
Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.
Aug 7, 20037.227NOYES
CVE-2003-1333HIGH
Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.
Dec 31, 200310.025NONO
CVE-2003-0498HIGH
Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are execute
Aug 7, 20037.223NONO
CVE-2018-17152MEDIUM
Intersystems Cache 2017.2.2.865.0 allows XXE.
Jul 11, 20196.421NONO
CVE-2018-17150MEDIUM
Intersystems Cache 2017.2.2.865.0 allows XSS.
Jul 11, 20196.121NONO
CVE-2018-17151MEDIUM
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
Jul 11, 20195.418NONO
CVE-2007-4427LOW
Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0.369.0 and 2007.1.1.420.0 allows remote
Aug 20, 20073.513NONO
CVE-2007-0437LOW
Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or H
Aug 20, 20073.513NONO
CVE-2004-2683LOW
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server.
Dec 31, 20042.111NONO
CVE-2004-2684LOW
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, relat
Dec 31, 20042.111NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
40%
30%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (30.0%)
Unknown7 (70.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (30.0%)
High0 (0.0%)
Unknown7 (70.0%)
User Interaction
None2 (20.0%)
Unknown7 (70.0%)
Required1 (10.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None1 (10.0%)
Unknown7 (70.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Intersystems.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Intersystems — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Intersystems's Products

View all 1 CNAs →

Top CWEs