Intersystems operates a narrowly focused product portfolio centered on the Cache database platform, which serves as a persistence and integration layer in healthcare, financial, and enterprise data environments. The vendor's vulnerability footprint concentrates around access-control weaknesses, code-injection flaws, and input-handling issues spanning web interfaces and data-query contexts, reflecting the application-facing attack surface of a widely embedded database system. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intersystems over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0497HIGH Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs. | Aug 7, 2003 | 7.2 | 27 | NO | YES |
CVE-2003-1333HIGH Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server. | Dec 31, 2003 | 10.0 | 25 | NO | NO |
CVE-2003-0498HIGH Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are execute | Aug 7, 2003 | 7.2 | 23 | NO | NO |
CVE-2018-17152MEDIUM Intersystems Cache 2017.2.2.865.0 allows XXE. | Jul 11, 2019 | 6.4 | 21 | NO | NO |
CVE-2018-17150MEDIUM Intersystems Cache 2017.2.2.865.0 allows XSS. | Jul 11, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-17151MEDIUM Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control. | Jul 11, 2019 | 5.4 | 18 | NO | NO |
Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0.369.0 and 2007.1.1.420.0 allows remote | Aug 20, 2007 | 3.5 | 13 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or H | Aug 20, 2007 | 3.5 | 13 | NO | NO |
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server. | Dec 31, 2004 | 2.1 | 11 | NO | NO |
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, relat | Dec 31, 2004 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intersystems.
Media articles that mention a CVE ID that affects a product developed by Intersystems — matched by CVE ID, not by vendor name.