← Back

Xsuite

xsuite

Vendor: Xceedium • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Broadcom
Xceedium
2Privileged Access Manager
Xsuite
Nov 21, 2024
Jun 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
1Xceedium
1Xsuite
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
1Xceedium
1Xsuite
May 13, 2026
Sep 25, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
1Xceedium
1Xsuite
May 13, 2026
Sep 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple hardcoded credentials in Xsuite 2.x.
1Xceedium
1Xsuite
May 6, 2026
Aug 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
1Xceedium
1Xsuite
May 6, 2026
Aug 13, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.