Lumension operates a modestly represented vulnerability profile focused on its PatchLink Update Server, a systems management and patch-deployment platform. The durable signal centers on SQL-injection vulnerabilities in the product, reflecting input-handling risks typical of database-backed administrative tools. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lumension over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3425HIGH FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/ | Jul 7, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-3430HIGH SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows | Jul 7, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-3426MEDIUM Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attacker | Jul 7, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lumension.
Media articles that mention a CVE ID that affects a product developed by Lumension — matched by CVE ID, not by vendor name.