Jedox maintains a modestly represented portfolio centered on business intelligence and analytics cloud platforms, including its core Jedox and Palo products, which sit within enterprise planning and data-analysis workflows. The recurring vulnerability patterns involve code injection, path traversal, and cross-site scripting—typical of web-based analytics and reporting interfaces that handle user input and file operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jedox over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47878HIGH Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Cons | May 2, 2023 | 8.8 | 56 | NO | YES |
CVE-2022-47875HIGH A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code. | May 2, 2023 | 8.8 | 41 | NO | YES |
CVE-2022-47874MEDIUM Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' | May 2, 2023 | 6.5 | 40 | NO | YES |
CVE-2022-47879HIGH A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute it | May 12, 2023 | 7.5 | 39 | NO | YES |
CVE-2022-47876HIGH The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts. | May 2, 2023 | 8.8 | 34 | NO | YES |
CVE-2022-47880MEDIUM An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a | May 12, 2023 | 5.3 | 31 | NO | YES |
CVE-2022-47877MEDIUM A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'. | May 2, 2023 | 5.4 | 29 | NO | YES |
CVE-2007-3581MEDIUM The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel | Jul 5, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jedox.
Media articles that mention a CVE ID that affects a product developed by Jedox — matched by CVE ID, not by vendor name.