Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jedox

First CVE: Jul 5, 2007Active for: 19 yearsTotal CVEs: 8

Jedox maintains a modestly represented portfolio centered on business intelligence and analytics cloud platforms, including its core Jedox and Palo products, which sit within enterprise planning and data-analysis workflows. The recurring vulnerability patterns involve code injection, path traversal, and cross-site scripting—typical of web-based analytics and reporting interfaces that handle user input and file operations. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jedox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 5, 2007
19 years ago
Most Recent CVE
May 12, 2023
1,170 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-47878HIGH
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Cons
May 2, 20238.856NOYES
CVE-2022-47875HIGH
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.
May 2, 20238.841NOYES
CVE-2022-47874MEDIUM
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections'
May 2, 20236.540NOYES
CVE-2022-47879HIGH
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute it
May 12, 20237.539NOYES
CVE-2022-47876HIGH
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.
May 2, 20238.834NOYES
CVE-2022-47880MEDIUM
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a
May 12, 20235.331NOYES
CVE-2022-47877MEDIUM
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.
May 2, 20235.429NOYES
CVE-2007-3581MEDIUM
The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel
Jul 5, 20075.015NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High2 (25.0%)
Unknown1 (12.5%)
User Interaction
None6 (75.0%)
Unknown1 (12.5%)
Required1 (12.5%)
Privileges Required
Low7 (87.5%)
High0 (0.0%)
None0 (0.0%)
Unknown1 (12.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
87.5% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jedox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jedox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jedox's Products

View all 1 CNAs →

Top CWEs