← Back

Moveit Web Application Firewall

moveit_web_application_firewall

Vendor: Progress • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Progress
5Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+2 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform...Show more
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.Show less
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privilege...Show more
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.Show less
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary op...Show more
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.Show less
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary op...Show more
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.Show less
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary op...Show more
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.Show less
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 10, 2026
Jun 4, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in mu...Show more
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpointsShow less
1Progress
6Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+3 more
Aug 10, 2026
Jan 13, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by...Show more
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parametersShow less