Helix Alm

Vendor:

First CVE: Apr 13, 2021 · Active for 5 years

3
Total CVEs
More Total CVEs than 68% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
4.4
Avg CVSS
Higher Avg CVSS than 5% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Helix Alm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2021
5 years ago
Most Recent CVE
Apr 15, 2025
468 days ago

CVE Severity & Scoring

Helix Alm3 CVEs
All CVEs352,785 CVEs
LowMedium
Attack Vector
Local1 (33.3%)
Network2 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (33.3%)
High2 (66.7%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (33.3%)
High1 (33.3%)
None1 (33.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
Apr 15, 20256.318NONO
The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software component
Apr 13, 20214.918NONO
In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
Jun 28, 20242.012NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Helix Alm

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2020.3.114.90.9%00