VYPR

Analytics Platform

by Knime

CVEs (4)

  • CVE-2022-31500HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.00

    In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.

  • CVE-2023-5562MedOct 12, 2023
    risk 0.40cvss 6.1epss 0.00

    An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When KNIME Analytics Platform is used as an executor for either KNIME Server or KNIME Business Hub several JavaScript-based view nodes do not sanitize the data that…

  • CVE-2022-44749MedNov 24, 2022
    risk 0.36cvss 5.5epss 0.00

    A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files being overwritten on the user's system. This vulnerability is also known as 'Zip-Slip'. An attacker can create a KNIME…

  • CVE-2021-45096MedDec 16, 2021
    risk 0.31cvss 4.7epss 0.01

    KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.