Solace develops a focused messaging and event-streaming platform centered on its PubSub and PubSub+ products, which serve as middleware for enterprise integration and real-time data distribution across distributed systems. The observed vulnerability profile reflects exposure patterns characteristic of credential-handling and information-disclosure issues in messaging infrastructure, where configuration and access-control boundaries are central to secure operation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Solace over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Solace.
Media articles that mention a CVE ID that affects a product developed by Solace — matched by CVE ID, not by vendor name.