Primekey
Primekey Ejbca: vulnerabilidades y CVE
Primekey Ejbca tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-3027 | Media (5.1) | 0.22% | — | 31 mar 2025 | The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an… |
| CVE-2025-3026 | Media (5.1) | 0.23% | — | 31 mar 2025 | The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulate the generated links and thus redirect… |
| CVE-2022-40711 | Media (4.8) | 0.46% | — | 1 ene 2023 | PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users. |
| CVE-2022-34831 | Crítica (9.8) | 0.52% | — | 14 sept 2022 | An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the… |
| CVE-2021-40089 | Baja (2.3) | 0.22% | — | 25 ago 2021 | An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration… |
| CVE-2021-40088 | Media (5.4) | 0.36% | — | 25 ago 2021 | An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests… |
| CVE-2021-40087 | Baja (2.7) | 0.41% | — | 25 ago 2021 | An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext… |
| CVE-2021-40086 | Baja (2.2) | 0.54% | — | 25 ago 2021 | An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an… |
| CVE-2020-28942 | Media (4.3) | 0.36% | — | 19 nov 2020 | An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client… |
| CVE-2020-25276 | Alta (7.3) | 0.49% | — | 11 sept 2020 | An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only… |
| CVE-2020-11631 | Media (6.5) | 1.1% | — | 8 abr 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of other bugs. This follow-on exploitation… |
| CVE-2020-11630 | Crítica (9.8) | 1.3% | — | 8 abr 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects… |
| CVE-2020-11629 | Alta (7.2) | 0.58% | — | 8 abr 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save… |
| CVE-2020-11628 | Media (5.3) | 0.86% | — | 8 abr 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions… |
| CVE-2020-11627 | Alta (8.8) | 0.45% | — | 8 abr 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI. |
| CVE-2020-11626 | Media (6.1) | 0.39% | — | 8 abr 2020 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets. |