Skyboxsecurity maintains a focused portfolio of vulnerability and risk management appliances and platform components, including its Skybox Platform, Manager Client, and View Appliance offerings, that occupy a prominent role in the vulnerability assessment and remediation workflows of enterprise security teams. Vulnerabilities affecting the vendor skew toward serious outcomes and have a moderate tendency toward public exploit availability, with the exposure recurring through application-layer weakness classes including information exposure, input validation failures, cross-site scripting, path traversal, and SQL injection that are characteristic of web-facing management interfaces. Defenders should treat updates for this vendor's core platform and appliance components as high-priority given their central role in vulnerability visibility and remediation orchestration; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skyboxsecurity over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2084HIGH Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote at | May 17, 2014 | 8.5 | 37 | NO | YES |
CVE-2015-9249CRITICAL An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element. | Jan 12, 2018 | 9.8 | 30 | NO | NO |
CVE-2015-9246CRITICAL An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archive containing a JSP file. The WAR file is sent to /skyboxview | Jan 12, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-14773HIGH Skybox Manager Client Application prior to 8.5.501 is prone to an elevation of privileges vulnerability during authentication of a valid user in a debugger-pause state. The vulnera | Oct 3, 2017 | 7.8 | 23 | NO | NO |
CVE-2015-9250HIGH An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tem | Jan 12, 2018 | 7.5 | 19 | NO | NO |
CVE-2017-14771MEDIUM Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploadin | Oct 3, 2017 | 5.5 | 18 | NO | NO |
CVE-2017-14770MEDIUM Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated attacker can access the passwo | Oct 3, 2017 | 5.5 | 18 | NO | NO |
CVE-2015-9248MEDIUM An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the title, Comments, or Description field to /skyboxview/webskybox/t | Jan 12, 2018 | 5.4 | 15 | NO | NO |
CVE-2015-9247MEDIUM An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a | Jan 12, 2018 | 5.4 | 15 | NO | NO |
Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid user | Oct 3, 2017 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skyboxsecurity.
Media articles that mention a CVE ID that affects a product developed by Skyboxsecurity — matched by CVE ID, not by vendor name.