Business Workflow

Vendor:

First CVE: Dec 18, 2020 · Active for 5 years

8
Total CVEs
More Total CVEs than 87% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Business Workflow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2020
5 years ago
Most Recent CVE
Dec 18, 2020
2,048 days ago

CVE Severity & Scoring

Business Workflow8 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (75.0%)
High0 (0.0%)
None2 (25.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction
Dec 18, 20208.826NONO
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not con
Dec 18, 20206.522NONO
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users.
Dec 18, 20206.521NONO
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.
Dec 18, 20205.318NONO
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restricti
Dec 18, 20204.317NONO
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a
Dec 18, 20204.317NONO
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No f
Dec 18, 20204.317NONO
In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to
Dec 18, 20204.316NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Business Workflow

Top CWEs

Versions

No cataloged versions.