Objectfirst's vulnerability footprint centers on its OOTBI product and revolves around application security weaknesses, primarily code injection, cryptographic randomness issues, and insufficient information placeholders that reflect input-handling and entropy-generation challenges. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Objectfirst over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44796CRITICAL An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows getting access to the Web UI without knowing credentials. For s | Nov 7, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-44794HIGH An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privilege | Nov 7, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-44795MEDIUM An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates | Nov 7, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Objectfirst.
Media articles that mention a CVE ID that affects a product developed by Objectfirst — matched by CVE ID, not by vendor name.