VYPR

Esb Runtime

by Qlik

CVEs (2)

  • CVE-2021-40684CriSep 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container…

  • CVE-2022-45589HigFeb 6, 2023
    risk 0.47cvss 7.2epss 0.01

    All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users of the provisioning service should upgrade to either 8.0.1-R2022-10-RT or 7.3.1-R2022-09-RT or a…