« Volver al listado

Xerox

Xerox Freeflow Core: vulnerabilidades y CVE

Xerox Freeflow Core tiene 8 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses2
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-2252Alta (7.5)0.27%—27 feb 2026
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow…
CVE-2026-2251Crítica (9.8)0.40%—27 feb 2026
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to…
CVE-2025-8356Crítica (9.8)19%—8 ago 2025
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run…
CVE-2025-8355Alta (7.5)8.6%—8 ago 2025
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side…
CVE-2024-47559Alta (8.8)0.50%—7 oct 2024
Authenticated RCE via Path Traversal
CVE-2024-47558Alta (8.8)0.50%—7 oct 2024
Authenticated RCE via Path Traversal
CVE-2024-47557Crítica (9.8)0.52%—7 oct 2024
Pre-Auth RCE via Path Traversal
CVE-2024-47556Crítica (9.8)0.52%—7 oct 2024
Pre-Auth RCE via Path Traversal

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application6
  2. T1059 Command and Scripting Interpreter5
  3. T1210 Exploitation of Remote Services2
  4. T1005 Data from Local System1
  5. T1090 Proxy1
  6. T1090.004 Domain Fronting1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Xerox