Known vulnerabilities in API Gateway November 2021 - page 2

Vendor: Axway
Software: API Gateway
Version: November 2021
Software CPE: cpe:2.3:a:axway:api_gateway:*:*:*:*:*:*:*:*
Total vulnerabilities: 64
Public exploits: 8
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting API Gateway version November 2021 API Gateway November 2021 is affected by 64 vulnerabilities: 1 critical, 9 high, 39 medium, 15 low Critical High Medium Low

Vulnerabilities (64)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU74265 - Improper Access Control
CWE-284 Low
No
No
November 2022 31.03.2023 SB2023033137
#VU74259 - URL Redirection to Untrusted Site ('Open Redirect')
CWE-601 Low
No
No
November 2022 31.03.2023 SB2023033137
#VU71999 - NULL Pointer Dereference
CVE-2023-0401
CWE-476 Medium
No
No
February 2023 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 52 more
#VU71998 - NULL Pointer Dereference
CVE-2023-0217
CWE-476 Medium
No
No
February 2023 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 49 more
#VU71997 - Release of invalid pointer or reference
CVE-2023-0216
CWE-763 Medium
No
No
February 2023 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 50 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
February 2023 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
February 2023 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71586 - Out-of-bounds write
CVE-2022-40152
CWE-787 Medium
No
No
November 2022 26.01.2023 SB2023012669
SB2023012670
SB2023013124
and 52 more
#VU71314 - Improper input validation
CVE-2022-40153
CWE-20 Medium
No
No
November 2022 18.01.2023 SB2023011841
SB2023012670
SB2023021321
and 21 more
#VU68896 - Memory corruption
CVE-2022-3786
CWE-119 Medium
Public exploit available
No
November 2022 01.11.2022 SB2022110132
SB2022110133
SB2022110144
and 44 more
#VU68895 - Memory corruption
CVE-2022-3602
CWE-119 High
Public exploit available
No
November 2022 01.11.2022 SB2022110132
SB2022110133
SB2022110144
and 45 more
#VU68438 - Improper input validation
CVE-2022-21626
CWE-20 Medium
No
No
November 2022 18.10.2022 SB2022101901
SB2022101902
SB2022102012
and 157 more
#VU68307 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42889
CWE-94 High
Public exploit available
Exploited
November 2022 14.10.2022 SB2022101405
SB2022102709
SB2022110306
and 91 more
#VU67532 - Use After Free
CVE-2022-40674
CWE-416 High
No
No
November 2022 21.09.2022 SB2022092118
SB2022092119
SB2022092317
and 111 more
#VU65497 - Improper input validation
CVE-2022-21540
CWE-20 Medium
No
No
August 2022 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 105 more
#VU59642 - Resource exhaustion
CVE-2021-45960
CWE-400 Medium
No
No
August 2022 17.01.2022 SB2022011711
SB2022011713
SB2022020902
and 56 more
#VU50410 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13947
CWE-79 Medium
No
No
August 2022 08.02.2021 SB2021020802
SB2023033136
#VU49330 - Insecure Temporary File
CVE-2020-15250
CWE-377 Low
No
No
August 2022 12.10.2020 SB2020101219
SB2021010712
SB2020110317
and 25 more
#VU17776 - Server-Side Request Forgery (SSRF)
CVE-2018-14721
CWE-918 Low
No
No
August 2022 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 23 more
#VU7241 - Integer overflow
CVE-2016-9063
CWE-190 Low
No
No
August 2022 25.06.2017 SB2017062501
SB2017062610
SB2017092304
and 7 more


Showing elements 21 - 40 out of 64