Ovaledge is a data governance and cloud data platform that manages access and visibility across databases and cloud storage services, with its vulnerability footprint concentrated in a single product line. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through application-layer weaknesses including cross-site scripting, improper authorization, insecure sensitive-data storage, cross-site request forgery, and incorrect default permissions—patterns typical of web-facing administrative interfaces handling privileged access. Defenders treating this vendor should prioritize patch deployment for the platform's authentication and data-handling mechanisms; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ovaledge over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30355CRITICAL OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is re | Oct 25, 2024 | 9.8 | 28 | NO | NO |
CVE-2022-30358HIGH OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is req | Oct 25, 2024 | 8.8 | 26 | NO | NO |
CVE-2022-30357HIGH OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is re | Oct 25, 2024 | 8.8 | 26 | NO | NO |
CVE-2022-30354HIGH OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclose | Oct 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-30360MEDIUM OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone pa | Oct 25, 2024 | 6.4 | 21 | NO | NO |
CVE-2022-30361MEDIUM OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed | Oct 25, 2024 | 5.3 | 18 | NO | NO |
CVE-2022-30359MEDIUM OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is | Oct 25, 2024 | 4.3 | 17 | NO | NO |
CVE-2022-30356MEDIUM OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is r | Oct 25, 2024 | 4.7 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ovaledge.
Media articles that mention a CVE ID that affects a product developed by Ovaledge — matched by CVE ID, not by vendor name.