Known vulnerabilities in webMethods Managed File Transfer - page 2

Software CPE: cpe:2.3:a:ibm_corporation:webmethods_managed_file_transfer:*:*:*:*:*:*:*:*
Total vulnerabilities: 90
Public exploits: 5
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting webMethods Managed File Transfer webMethods Managed File Transfer is affected by 90 known vulnerabilities: 1 critical, 7 high, 59 medium, 23 low Critical High Medium Low

Vulnerabilities (90)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107988 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2020-7772
CWE-1321 Critical
No
No
- 28.04.2025 SB2020111502
SB2025042830
#VU95441 - Missing release of memory after effective lifetime
CVE-2024-26462
CWE-401 Medium
No
No
- 07.08.2024 SB2024040939
SB2024080724
SB2024080725
and 18 more
#VU93518 - Improper input validation
CVE-2024-37370
CWE-20 Medium
No
No
- 01.07.2024 SB2024070148
SB2024070491
SB2024070496
and 96 more
#VU93424 - Out-of-bounds read
CVE-2024-5535
CWE-125 Low
Available
No
- 27.06.2024 SB2024062720
SB20240717135
SB2024072154
and 157 more
#VU89861 - Use After Free
CVE-2024-4741
CWE-416 Medium
No
No
- 29.05.2024 SB2024052912
SB2024060803
SB2024060804
and 88 more
#VU89220 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-30172
CWE-835 Medium
No
No
- 07.05.2024 SB2024050731
SB2024061019
SB20240611170
and 62 more
#VU89219 - Observable discrepancy
CVE-2024-30171
CWE-203 Medium
No
No
- 07.05.2024 SB2024050731
SB2024050734
SB2024061019
and 59 more
#VU88226 - Missing release of memory after effective lifetime
CVE-2024-26461
CWE-401 Medium
No
No
- 09.04.2024 SB2024040939
SB2024040943
SB20240611102
and 46 more
#VU88225 - Missing release of memory after effective lifetime
CVE-2024-26458
CWE-401 Medium
No
No
- 09.04.2024 SB2024040938
SB2024040943
SB20240611102
and 47 more
#VU87850 - Missing Release of Resource after Effective Lifetime
CVE-2024-2398
CWE-772 Medium
No
No
- 27.03.2024 SB2024032713
SB2024032740
SB2024032744
and 106 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
- 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU83900 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46218
CWE-200 Low
No
No
- 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 87 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
- 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU79561 - Out-of-bounds write
CVE-2023-4016
CWE-787 High
No
No
- 15.08.2023 SB2023081548
SB20230821203
SB2023082925
and 49 more
#VU77476 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4231
CWE-79 Low
No
No
- 16.06.2023 SB2022052637
SB2023061625
SB2023062315
and 3 more
#VU76757 - Missing release of memory after effective lifetime
CVE-2023-2602
CWE-401 Medium
No
No
- 01.06.2023 SB2023060126
SB2023061452
SB2023070343
and 74 more
#VU76238 - Expected Behavior Violation
CVE-2023-28322
CWE-440 Medium
No
No
- 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 88 more
#VU76237 - Improper Certificate Validation
CVE-2023-28321
CWE-295 Medium
No
No
- 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 99 more
#VU73829 - State Issues
CVE-2023-27536
CWE-371 Medium
No
No
- 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 80 more
#VU72703 - Improper Control of Filename for Include/Require Statement in PHP Program
CVE-2023-2603
CWE-98 High
No
No
- 01.03.2023 SB2023030118
SB2023060126
SB2023061452
and 87 more


Showing elements 21 - 40 out of 90