Saison's vulnerability footprint centers on DataSpider Servista, an integration and data-management platform, with observed weaknesses concentrated in XML external entity handling and credential management. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saison over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48006CRITICAL Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file | Sep 29, 2025 | 9.1 | 29 | NO | NO |
CVE-2023-28937HIGH DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are | Jun 1, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saison.
Media articles that mention a CVE ID that affects a product developed by Saison — matched by CVE ID, not by vendor name.