1e

Platform

5 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 01.08.2024 17:16:09
  • Last modified 20.05.2025 09:15:20

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users. Note: 1E Platform's component utilizing the third-p...

  • EPSS 0.18%
  • Published 06.11.2023 13:15:10
  • Last modified 20.05.2025 09:15:20

The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message parameters, which allows for a specially crafted input to perform arbitrary...

  • EPSS 0.1%
  • Published 06.11.2023 13:15:09
  • Last modified 12.06.2025 15:15:32

The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM...

  • EPSS 0.1%
  • Published 06.11.2023 13:15:09
  • Last modified 12.06.2025 15:15:32

The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYST...

  • EPSS 0.1%
  • Published 13.10.2023 13:15:11
  • Last modified 20.05.2025 09:15:20

Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.  Application of the relevant hotfix remediates this issue. for v8.1.2 apply hotfix Q23166 for v8.4.1 apply hotfix Q23164 for v9.0.1 ap...