Skip to main content

Vendor archive

mulesoft CVEs

Beta · best-effort

6 CVEs tagged to vendor mulesoft3 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2020-6937

Published May 29, 2020

A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resourc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10991

Published Mar 27, 2020

Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15631

Published Dec 2, 2019

Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13116

Published Oct 16, 2019

The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collecti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9000

Published Nov 20, 2014

Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1