SOS develops a modestly represented job-scheduling and automation platform where the observed vulnerability signal centers on web-facing input and path-handling issues, particularly path traversal and cross-site scripting flaws. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sos over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5392MEDIUM XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or dir | Sep 23, 2014 | 5.8 | 22 | NO | NO |
CVE-2022-2806MEDIUM It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev | Sep 1, 2022 | 5.5 | 20 | NO | NO |
CVE-2015-7529HIGH sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as | Nov 6, 2017 | 7.8 | 20 | NO | NO |
CVE-2014-5391MEDIUM Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject | Sep 11, 2014 | 4.3 | 19 | NO | NO |
CVE-2014-5393MEDIUM Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with t | Sep 11, 2014 | 4.0 | 18 | NO | NO |
CVE-2015-3171MEDIUM sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of t | Jul 25, 2017 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sos.
Media articles that mention a CVE ID that affects a product developed by Sos — matched by CVE ID, not by vendor name.