← Back

Enterprise Content Management

enterprise_content_management

Vendor: Ericsson • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ericsson
1Enterprise Content Management
Jun 17, 2026
Sep 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.
1Ericsson
1Enterprise Content Management
Jun 17, 2026
Sep 17, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.