Simmeth's vulnerability profile centers on a specialized supply-chain management application, Lieferantenmanager, where its disclosed weaknesses cluster around access control and application-layer input-handling issues including path traversal, cross-site scripting, and SQL injection. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the sensitivity of procurement and vendor data that such platforms handle. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simmeth over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44015CRITICAL An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary co | Dec 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-44013CRITICAL An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because the password in a Credential Object is not c | Dec 25, 2022 | 9.1 | 29 | NO | NO |
CVE-2022-44017HIGH An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out | Dec 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-44016HIGH An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationS | Dec 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-44014MEDIUM An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQL tables. This leaks all user passwords a | Dec 25, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-44012MEDIUM An issue was discovered in /DS/LM_API/api/SelectionService/InsertQueryWithActiveRelationsReturnId in Simmeth Lieferantenmanager before 5.6. An attacker can execute JavaScript code | Dec 25, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simmeth.
Media articles that mention a CVE ID that affects a product developed by Simmeth — matched by CVE ID, not by vendor name.