Sawmill is a focused log-analysis and reporting platform whose vulnerability profile, despite a narrow product scope, has drawn attention in the vulnerability landscape due to its role in processing and exposing operational data. The vendor's disclosures skew toward serious outcomes, reaching critical severity in a meaningful share of cases, and frequently acquire public exploit code; the recurring weakness classes center on input-validation and cross-site scripting issues alongside improper handling of sensitive information exposure, typical of web-facing analytics applications. Defenders should prioritize visibility into internet-exposed instances and treat updates as moderately urgent; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sawmill over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5496CRITICAL Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash. | Mar 15, 2017 | 9.8 | 36 | NO | YES |
CVE-2000-0589HIGH SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration. | Jun 26, 2000 | 7.5 | 32 | NO | YES |
CVE-2000-0588MEDIUM SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as | Jun 26, 2000 | 5.0 | 25 | NO | YES |
CVE-2002-0265MEDIUM Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file. | May 29, 2002 | 4.6 | 21 | NO | YES |
CVE-2005-1900HIGH Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license. | Jun 9, 2005 | 7.5 | 20 | NO | NO |
CVE-2013-4947HIGH Unspecified vulnerability in the update and build database page in Sawmill before 8.6.3 allows remote attackers to have unknown impact and attack vectors. | Jul 29, 2013 | 7.5 | 19 | NO | NO |
CVE-2010-1079MEDIUM Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Mar 23, 2010 | 4.3 | 16 | NO | NO |
CVE-2005-2950MEDIUM Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request. | Sep 16, 2005 | 4.3 | 14 | NO | NO |
CVE-2005-1901MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the username in the Add User windo | Jun 9, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sawmill.
Media articles that mention a CVE ID that affects a product developed by Sawmill — matched by CVE ID, not by vendor name.