Trimble
Trimble Tm4web: vulnerabilidades y CVE
Trimble Tm4web tiene 3 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-35499 | Alta (7.1) | 0.29% | — | 4 sept 2026 | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL. |
| CVE-2022-35497 | Media (5.4) | 0.26% | — | 4 sept 2026 | In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint. |
| CVE-2023-27195 | Crítica (9.8) | 1.0% | — | 8 nov 2024 | Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve the last registration access code and use this access code to register a valid account. via a PUT… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Trimble
Sketchup Viewer · 27Sketchup · 12Sps851 · 2Infrastructure Gnss Series Receiver Netr8 · 1Infrastructure Gnss Series Receiver Netr9 · 1Cityworks · 1Sketchup Desktop · 1Sketchup Webhelper · 1Infrastructure Netrs Receiver · 1Infrastructure Gnss Series Receiver Netr3 · 1Infrastructure Gnss Series Receiver Netr5 · 1