Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Softwareag

First CVE: Jul 26, 2019Active for: 7 yearsTotal CVEs: 13
33.3
VTI Score
Medium

Software AG operates a portfolio of enterprise integration, data management, and business process automation platforms including MashZone, ARIS, webMethods, and related middleware products that serve integration and analytics functions in large organizations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weaknesses characteristic of large integration and data-processing systems: deserialization of untrusted data, XML external entity injection, resource-exhaustion conditions, improper access control, and code-injection vectors that reflect the parsing and dynamic-execution demands of middleware and orchestration layers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Softwareag over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2019
6 years ago
Most Recent CVE
Jan 7, 2026
198 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-13990CRITICAL
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Jul 26, 20199.840NONO
CVE-2020-35469CRITICAL
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS containe
Dec 16, 20209.831NONO
CVE-2021-33207CRITICAL
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
Apr 5, 20229.830NONO
CVE-2023-0925CRITICAL
Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfac
Sep 6, 20239.827NONO
CVE-2023-39017CRITICAL
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is expl
Jul 28, 20239.826NONO
CVE-2021-40650MEDIUM
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
Jun 14, 20226.524NONO
CVE-2021-40649MEDIUM
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
Jun 14, 20226.524NONO
CVE-2021-33523HIGH
MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can execute arbitrary commands on the underl
Mar 30, 20227.224NONO
CVE-2021-33581HIGH
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PP
Mar 30, 20227.224NONO
CVE-2021-33208HIGH
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.
Mar 30, 20227.224NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
38%
23%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low1 (7.7%)
High3 (23.1%)
None9 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Softwareag.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Softwareag — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Softwareag's Products

View all 3 CNAs →

Top CWEs