« Volver al listado

Zlt2000

Zlt2000 Microservices-platform: vulnerabilidades y CVE

Zlt2000 Microservices-platform tiene 7 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses4
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-92469Alta (7.2)0.54%—16 sept 2026
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can…
CVE-2026-92468Alta (7.1)0.48%—16 sept 2026
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name…
CVE-2026-92467Alta (8.7)0.46%—16 sept 2026
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the…
CVE-2026-92466Alta (8.7)0.91%—16 sept 2026
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication.…
CVE-2025-8841Baja (2.1)0.30%—11 ago 2025
A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file…
CVE-2025-8738Media (5.5)0.37%—8 ago 2025
A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The…
CVE-2025-8737Baja (2)0.24%—8 ago 2025
A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform up to 6.0.0. This affects the function onLogoutSuccess of the file…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1078.001 Default Accounts2
  3. T1005 Data from Local System1
  4. T1531 Account Access Removal1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.