Software AG operates a portfolio of enterprise integration, data management, and business process automation platforms including MashZone, ARIS, webMethods, and related middleware products that serve integration and analytics functions in large organizations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weaknesses characteristic of large integration and data-processing systems: deserialization of untrusted data, XML external entity injection, resource-exhaustion conditions, improper access control, and code-injection vectors that reflect the parsing and dynamic-execution demands of middleware and orchestration layers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softwareag over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13990CRITICAL initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | Jul 26, 2019 | 9.8 | 40 | NO | NO |
CVE-2020-35469CRITICAL The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS containe | Dec 16, 2020 | 9.8 | 31 | NO | NO |
CVE-2021-33207CRITICAL The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code. | Apr 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-0925CRITICAL Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfac | Sep 6, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-39017CRITICAL quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is expl | Jul 28, 2023 | 9.8 | 26 | NO | NO |
CVE-2021-40650MEDIUM In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set. | Jun 14, 2022 | 6.5 | 24 | NO | NO |
CVE-2021-40649MEDIUM In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set. | Jun 14, 2022 | 6.5 | 24 | NO | NO |
CVE-2021-33523HIGH MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can execute arbitrary commands on the underl | Mar 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-33581HIGH MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PP | Mar 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-33208HIGH The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file. | Mar 30, 2022 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softwareag.
Media articles that mention a CVE ID that affects a product developed by Softwareag — matched by CVE ID, not by vendor name.