Redwood's vulnerability footprint centers on a narrow set of enterprise integration and file-transfer products, including SAP Business Process Automation, Report2Web, and JScape MFT, that handle trusted data flows and file operations in business-critical contexts. The vendor's recurring weakness classes—untrusted deserialization, cross-domain resource references, path traversal, cross-site scripting, and XML external entity injection—reflect the data-parsing and access-control surface inherent to middleware and file-handling platforms, and vulnerabilities here frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redwood over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4528HIGH Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its ma | Sep 7, 2023 | 7.2 | 36 | NO | NO |
CVE-2021-26710MEDIUM A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter. | Feb 5, 2021 | 6.1 | 32 | NO | YES |
CVE-2018-2401HIGH SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerab | Mar 14, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-2400HIGH Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted. | Mar 14, 2018 | 7.5 | 25 | NO | NO |
CVE-2021-26711MEDIUM A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/defa | Feb 5, 2021 | 5.3 | 19 | NO | NO |
CVE-2018-2366MEDIUM SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representin | Mar 14, 2018 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redwood.
Media articles that mention a CVE ID that affects a product developed by Redwood — matched by CVE ID, not by vendor name.