Vendor
Soffidiam
Products
2
CVEs
3
Across products
3
Status
Private
Products
2- 2 CVEs
- 1 CVE
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39669 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security. | ||
| CVE-2017-9363 | Cri | 0.64 | 9.8 | 0.03 | Jun 2, 2017 | Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request. | ||
| CVE-2025-32408 | Low | 0.16 | 2.5 | 0.00 | Apr 21, 2025 | In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled. |
- risk 0.64cvss 9.8epss 0.01
In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.
- risk 0.64cvss 9.8epss 0.03
Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.
- risk 0.16cvss 2.5epss 0.00
In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.