Smartclient is a web-application framework and UI toolkit that has surfaced vulnerabilities concentrated in path-traversal flaws, XML external entity handling, and information-disclosure issues in error messaging. These weakness classes reflect the framework's role in server-side request processing and client-server data exchange; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartclient over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9352CRITICAL An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOpe | Feb 23, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-9354HIGH An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomor | Feb 23, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-9353HIGH An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomor | Feb 23, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-9351MEDIUM An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML | Feb 23, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartclient.
Media articles that mention a CVE ID that affects a product developed by Smartclient — matched by CVE ID, not by vendor name.