VYPR

Helix ALM

by Rogue Wave

CVEs (3)

  • CVE-2024-11084MedApr 15, 2025
    risk 0.41cvss epss 0.00

    Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.

  • CVE-2021-28973MedApr 13, 2021
    risk 0.32cvss 4.9epss 0.01

    The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.

  • CVE-2024-3995LowJun 28, 2024
    risk 0.13cvss epss 0.01

    In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.