← Back

Open Automation Software

open_automation_software

Vendor: Openautomationsoftware • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openautomationsoftware
1Open Automation Software
Jan 23, 2025
Dec 6, 2024
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report execute...Show more
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.Show less
1Openautomationsoftware
1Open Automation Software
Nov 4, 2025
Apr 3, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to unexpe...Show more
An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Openautomationsoftware
1Open Automation Software
Nov 4, 2025
Apr 3, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can cause the r...Show more
A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Openautomationsoftware
1Open Automation Software
Nov 4, 2025
Apr 3, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary fil...Show more
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Openautomationsoftware
1Open Automation Software
Nov 4, 2025
Apr 3, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creatio...Show more
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.Show less