Sapphireims is an incident management system with a narrow product scope, yet holds a prominent position among vendors tracked for vulnerabilities affecting specialized security and operations infrastructure. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, concentrating around authentication and access-control weaknesses such as hard-coded credentials, missing authentication gates on critical functions, and improper permission assignment, alongside input-handling flaws including cross-site request forgery and sensitive information disclosure. Defenders should treat patches for this vendor as urgent given the critical nature of the exposure and the sensitive data typically managed by incident management platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sapphireims over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25566CRITICAL In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not require a JSESSIONID in this reques | Aug 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-25565CRITICAL In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the a | Aug 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-25560CRITICAL In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the a | Aug 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-25563CRITICAL In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature | Aug 11, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-25564HIGH In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) | Aug 11, 2021 | 8.8 | 27 | NO | NO |
CVE-2017-16630HIGH In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Direct Object Reference (IDOR) in | Aug 11, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-25561HIGH SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the client. | Aug 11, 2021 | 7.8 | 24 | NO | NO |
CVE-2017-16632HIGH In SapphireIMS 4097_1, the password in the database is stored in Base64 format. | Aug 11, 2021 | 7.5 | 24 | NO | NO |
CVE-2017-16629HIGH In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives out for each type of user on the Login form. For "Incorrect | Aug 11, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-25562MEDIUM In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms like account resent. | Aug 11, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sapphireims.
Media articles that mention a CVE ID that affects a product developed by Sapphireims — matched by CVE ID, not by vendor name.