Known vulnerabilities in apache-ivy

Vendor: SUSE
Software: apache-ivy
Software CPE: cpe:2.3:o:suse:apache-ivy:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 2
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting apache-ivy apache-ivy is affected by 2 known vulnerabilities: 1 high, 1 low Critical High Medium Low

Vulnerabilities (2)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144731 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-26032
CWE-22 Low
No
No
2.6.0-150200.3.12.1 24.08.2026 SB20260824105
SB20260824106
SB20260824119
and 2 more
#VU79749 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2022-46751
CWE-611 High
No
No
2.5.2-150200.3.9.1 21.08.2023 SB2023082105
SB2023090730
SB2023101825
and 18 more