Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Catalog HIGH 7.5
CVE-2023-36301

Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.

Fix: 8.0-20230221+
Fix from $1,950 2023-06-26
Data Catalog HIGH 7.5
CVE-2023-33247

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed …

Fix: 8.0-20230413+
Fix from $1,950 2023-05-26
Studio HIGH 7.5
CVE-2023-31444

In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the micro…

Fix: 7.3.1-r2022-10 / 8.0.1-r2022-09+
Fix from $1,950 2023-04-28
Data Catalog MEDIUM 5.5
CVE-2023-26263

All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/licen…

Fix: 8.0-20230110+
Fix from $1,600 2023-04-13
Data Catalog MEDIUM 5.5
CVE-2023-26264

All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.

Fix: 8.0-20220907+
Fix from $1,600 2023-04-13
Esb Runtime HIGH 7.2
CVE-2022-45589

All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the prov…

Fix: 7.3.1-r2022-09-rt / 8.0.1-r2022-10-rt+
Fix from $1,950 2023-02-06
Remote Engine Gen 2 HIGH 7.8
CVE-2022-45588

All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should do…

Mitigation only
Fix from $1,950 2023-02-03
Administration Center MEDIUM 5.3
CVE-2022-30332

In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset atte…

Mitigation only
Fix from $1,600 2023-01-10
Open Studio CRITICAL 9.8
CVE-2021-4311

A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handl…

Fix: 20230102_1935+
Fix from $2,300 2023-01-09
Administration Center MEDIUM 6.1
CVE-2022-31648

Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint. The issue is fixed for versions…

Mitigation only
Fix from $1,600 2022-05-26
Administration Center MEDIUM 6.5
CVE-2022-29942

Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HT…

Mitigation only
Fix from $1,600 2022-05-04
Administration Center MEDIUM 6.5
CVE-2022-29943

Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access…

Mitigation only
Fix from $1,600 2022-05-04
Data Catalog CRITICAL 9.8
CVE-2021-42837

An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the nati…

Fix: 7.3-20210930+
Fix from $2,300 2021-11-05
Esb Runtime CRITICAL 9.1
CVE-2021-40684

Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which all…

Fix: 7.1.1-r2021-09+
Fix from $2,300 2021-09-22
Restlet CRITICAL 9.8
CVE-2014-2228

The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

Fix: after 2.1.7
Fix from $2,300 2020-02-19
Restlet HIGH 7.5
CVE-2012-2656

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive informa…

Patch available
Fix from $1,950 2019-12-18