Filtered by vendor Digiwin Subscriptions
Filtered by product Business Process Management Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-32457 1 Digiwin 1 Business Process Management 2024-09-16 5.3 Medium
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
CVE-2022-32458 1 Digiwin 1 Business Process Management 2024-09-16 7.5 High
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
CVE-2022-32456 1 Digiwin 1 Business Process Management 2024-09-16 9.8 Critical
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.