Soumu operates a suite of specialized administrative and workflow systems for Japanese radio-license processing and government operations, with a narrow but targeted exposure footprint. The recurring vulnerability signal centers on application-layer security weaknesses including untrusted search-path resolution, improper authentication mechanisms, and SQL-injection flaws in database-facing components, reflecting common risks in legacy administrative software. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Soumu over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5958HIGH Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via | May 17, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-5957HIGH Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain pri | May 17, 2019 | 7.8 | 24 | NO | NO |
CVE-2006-6706MEDIUM SQL injection vulnerability in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allows remote | Dec 23, 2006 | 6.5 | 17 | NO | NO |
CVE-2006-6705MEDIUM Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01 | Dec 23, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Soumu.
Media articles that mention a CVE ID that affects a product developed by Soumu — matched by CVE ID, not by vendor name.