Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sapphireims

First CVE: Aug 11, 2021Active for: 5 yearsTotal CVEs: 11
51.4
VTI Score
TOP TARGET

Sapphireims is an incident management system with a narrow product scope, yet holds a prominent position among vendors tracked for vulnerabilities affecting specialized security and operations infrastructure. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, concentrating around authentication and access-control weaknesses such as hard-coded credentials, missing authentication gates on critical functions, and improper permission assignment, alongside input-handling flaws including cross-site request forgery and sensitive information disclosure. Defenders should treat patches for this vendor as urgent given the critical nature of the exposure and the sensitive data typically managed by incident management platforms; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
11.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sapphireims over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 2021
4 years ago
Most Recent CVE
Aug 11, 2021
1,810 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25566CRITICAL
In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not require a JSESSIONID in this reques
Aug 11, 20219.831NONO
CVE-2020-25565CRITICAL
In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the a
Aug 11, 20219.831NONO
CVE-2020-25560CRITICAL
In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the a
Aug 11, 20219.831NONO
CVE-2020-25563CRITICAL
In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature
Aug 11, 20219.830NONO
CVE-2020-25564HIGH
In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks)
Aug 11, 20218.827NONO
CVE-2017-16630HIGH
In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Direct Object Reference (IDOR) in
Aug 11, 20218.827NONO
CVE-2020-25561HIGH
SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the client.
Aug 11, 20217.824NONO
CVE-2017-16632HIGH
In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
Aug 11, 20217.524NONO
CVE-2017-16629HIGH
In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives out for each type of user on the Login form. For "Incorrect
Aug 11, 20217.524NONO
CVE-2020-25562MEDIUM
In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms like account resent.
Aug 11, 20216.522NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
18%
45%
36%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None7 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sapphireims.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sapphireims — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sapphireims's Products

View all 1 CNAs →

Top CWEs