TopQuadrant's vulnerability profile centers on its TopBraid EDG product, a semantic data governance and knowledge-graph platform, with recurring disclosures clustering around credential and data-protection issues such as cleartext storage of sensitive information, improper XML external entity handling, insufficiently protected credentials, and storage of passwords in recoverable formats. These patterns reflect the challenges of securing systems that process and expose sensitive configuration and authentication data across enterprise knowledge bases; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Topquadrant over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45744MEDIUM TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt ex | Sep 27, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-45745MEDIUM TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8 | Sep 27, 2024 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Topquadrant.
Media articles that mention a CVE ID that affects a product developed by Topquadrant — matched by CVE ID, not by vendor name.