Xceedium develops a focused suite of privileged-access and identity-management products centered on its XSuite platform, which sits in the authentication and credential-handling path of enterprise infrastructure. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, driven by recurring application-layer weakness classes—improper input validation, path traversal, cross-site scripting, SQL injection, and open redirect—that are characteristic of web-facing administrative interfaces. Defenders should treat XSuite updates as high-priority given the vendor's role in access control; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xceedium over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4664CRITICAL An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | Jun 18, 2018 | 9.8 | 45 | NO | YES |
CVE-2015-4667CRITICAL Multiple hardcoded credentials in Xsuite 2.x. | Sep 25, 2017 | 9.8 | 39 | NO | YES |
CVE-2015-4666MEDIUM Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot doub | Aug 13, 2015 | 5.0 | 37 | NO | YES |
CVE-2015-4668MEDIUM Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl pa | Sep 25, 2017 | 6.1 | 35 | NO | YES |
CVE-2015-4669HIGH The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system. | Sep 25, 2017 | 7.8 | 29 | NO | YES |
CVE-2015-4665MEDIUM Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName para | Aug 13, 2015 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xceedium.
Media articles that mention a CVE ID that affects a product developed by Xceedium — matched by CVE ID, not by vendor name.