Saleslogix maintains a niche customer relationship management and business intelligence product line, with a focused vulnerability footprint centered on its Corporation eViewer component. The observed disclosures reflect application-layer exposure rather than a broad systemic pattern, and current severity, exploitation, and remediation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saleslogix over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1612MEDIUM Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request. | Oct 18, 2004 | 5.0 | 25 | NO | YES |
CVE-2004-1608HIGH SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation. | Oct 18, 2004 | 7.5 | 24 | NO | NO |
CVE-2004-1605HIGH SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator. | Oct 14, 2004 | 7.5 | 24 | NO | NO |
CVE-2000-0278MEDIUM The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user. | Aug 3, 2000 | 5.0 | 24 | NO | YES |
CVE-2004-1607MEDIUM slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the p | Oct 18, 2004 | 5.0 | 20 | NO | NO |
CVE-2004-1610HIGH SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.A | Oct 18, 2004 | 7.5 | 20 | NO | NO |
CVE-2004-1606MEDIUM slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the E | Oct 18, 2004 | 6.4 | 18 | NO | NO |
CVE-2004-1609MEDIUM SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access. | Oct 18, 2004 | 5.0 | 15 | NO | NO |
CVE-2004-1611MEDIUM SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the se | Oct 18, 2004 | 5.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saleslogix.
Media articles that mention a CVE ID that affects a product developed by Saleslogix — matched by CVE ID, not by vendor name.