Incoming Goods Suite
by SICK AG
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-11075 | Hig | 0.57 | 8.8 | 0.00 | Nov 19, 2024 | A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting… | ||
| CVE-2026-22646 | 0.00 | — | 0.00 | Jan 15, 2026 | Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the… | |||
| CVE-2026-22645 | 0.00 | — | 0.00 | Jan 15, 2026 | The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components. | |||
| CVE-2026-22644 | 0.00 | — | 0.00 | Jan 15, 2026 | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access. |
- risk 0.57cvss 8.8epss 0.00
A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting…
- CVE-2026-22646Jan 15, 2026risk 0.00cvss —epss 0.00
Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the…
- CVE-2026-22645Jan 15, 2026risk 0.00cvss —epss 0.00
The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components.
- CVE-2026-22644Jan 15, 2026risk 0.00cvss —epss 0.00
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.