Servisnet develops the Tessa platform, a narrowly scoped product line with a durable signal of access-control weaknesses including authorization bypass through user-controlled keys and improper authentication mechanisms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Servisnet over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22832CRITICAL An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request. | Feb 6, 2022 | 9.8 | 50 | NO | YES |
CVE-2022-22831CRITICAL An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header. | Feb 6, 2022 | 9.8 | 47 | NO | YES |
CVE-2022-22833HIGH An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request. | Feb 6, 2022 | 7.5 | 40 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Servisnet.
Media articles that mention a CVE ID that affects a product developed by Servisnet — matched by CVE ID, not by vendor name.