Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webperfect Image Suite CRITICAL 10.0
CVE-2026-39906

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthentic…

Mitigation only
Fix from $2,300 2026-04-14
Webperfect Image Suite CRITICAL 10.0
CVE-2026-39907

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts un…

Mitigation only
Fix from $2,300 2026-04-14
Stealth HIGH 7.5
CVE-2024-23758

An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.log file.

Mitigation only
Fix from $1,950 2024-02-20
Data Exchange Management Studio HIGH 8.8
CVE-2022-32555

Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, …

Mitigation only
Fix from $1,950 2022-09-13
Messaging Integration Services CRITICAL 9.8
CVE-2021-43394

Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm.…

Mitigation only
Fix from $2,300 2022-01-24
Clearpath Mcp Tcp\/ip Networking Services HIGH 7.5
CVE-2021-45445

Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.

No fix yet
Fix from $1,950 2022-01-12
Cargo Mobile HIGH 7.5
CVE-2021-43388

Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addres…

Fix: 1.2.29+
Fix from $1,950 2021-12-14
Stealth MEDIUM 6.7
CVE-2021-35056

Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might…

Fix: 5.1.025.0 / 6.0.055.0+
Fix from $1,600 2021-07-15
Data Exchange Management Studio MEDIUM 5.4
CVE-2020-35542

Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack.

Fix: after 5.0.34
Fix from $1,600 2021-04-27
Stealth HIGH 7.8
CVE-2021-3141

In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who …

Fix: 6.0.025.0+
Fix from $1,950 2021-03-18
Stealth HIGH 7.8
CVE-2020-24620

Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal creden…

Fix: 4.0.134+
Fix from $1,950 2020-10-01
Stealth CRITICAL 9.8
CVE-2020-12053

In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized withou…

Fix: 5.0.026+
Fix from $2,300 2020-06-22
Algol Compiler HIGH 8.8
CVE-2020-12647

Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances rel…

Fix: 58.1a.15 / 59.1a.9+
Fix from $1,950 2020-05-21
Stealth HIGH 7.5
CVE-2019-18193

In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3…

Mitigation only
Fix from $1,950 2020-02-03
Mcp Firmware HIGH 8.7
CVE-2019-18386

Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecified impact when receiving spe…

Mitigation only
Fix from $1,950 2020-01-07
Stealth Svg HIGH 7.5
CVE-2018-8049

The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux…

Fix: 3.0.1999 / 3.2.030+
Fix from $1,950 2018-04-03
Clearpath Eportal Manager HIGH 8.1
CVE-2018-8802

SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecifie…

Fix: 2.2.81 / 2.3.82+
Fix from $1,950 2018-03-26
Clearpath Mcp MEDIUM 5.9
CVE-2018-5762

The TLS implementation in the TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 58.1 before 58.160, 59.1 before 059.1a.17 (IC #…

Fix: 58.160 / 059.1a.17+
Fix from $1,600 2018-02-26
Stealth HIGH 7.8
CVE-2018-6592

Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by leveraging improper cleanup of m…

Fix: 3.3.016.1+
Fix from $1,950 2018-02-19
Mcp Firmware HIGH 7.8
CVE-2017-13684

Unisys Libra 64xx and 84xx and FS601 class systems with MCP-FIRMWARE before 43.211 allow remote authenticated users to cause a denial of service (pro…

Fix: after 43.185
Fix from $1,950 2017-09-30
Mobigate MEDIUM 5.9
CVE-2016-7805

The mobiGate App for Android version 2.2.1.2 and earlier and mobiGate App for iOS version 2.2.4.1 and earlier do not verify X.509 certificates from S…

Fix: after 2.2.4.1
Fix from $1,600 2017-06-09
Secure Partitioning MEDIUM 6.7
CVE-2017-5873

Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan hors…

No fix yet
Fix from $1,600 2017-04-11
Clearpath Mcp HIGH 7.5
CVE-2017-5872

The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when runni…

Mitigation only
Fix from $1,950 2017-03-10
Mcp Firmware MEDIUM 6.8
CVE-2015-4049

Unisys Libra 43xx, 63xx, and 83xx, and FS600 class systems with MCP-FIRMWARE 40.0 before 40.0IC4 Build 270 might allow remote authenticated users to …

Mitigation only
Fix from $1,600 2017-02-03
Business Information Server HIGH 10.0
CVE-2009-1628EPSS 5%

Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2009-06-26
Clearpath Mcp HIGH 7.8
CVE-2002-2179

The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan …

Patch available
Fix from $1,950 2002-12-31