Aveva Application Server vulnerabilities

4 known vulnerabilities affecting aveva/application_server.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4

Vulnerabilities

Page 1 of 1
CVE-2025-8386HIGHCVSS 7.2≤ Versions 2023 R2 SP1 P022025-11-15
CVE-2025-8386 [HIGH] CWE-80 CVE-2025-8386: The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfi The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time
cvelistv5nvd
CVE-2024-7113HIGHCVSS 8.7≤ 2023 R2 P012024-08-13
CVE-2024-7113 [HIGH] CWE-770 CVE-2024-7113: If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resource If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.
cvelistv5nvd
CVE-2023-33873HIGHCVSS 7.8≤ 2020 R2 SP1 P012023-11-15
CVE-2023-33873 [HIGH] CWE-250 CVE-2023-33873: This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user wi This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
cvelistv5nvd
CVE-2023-34982HIGHCVSS 7.1≤ 2020 R2 SP1 P012023-11-15
CVE-2023-34982 [HIGH] CWE-73 CVE-2023-34982: This external control vulnerability, if exploited, could allow a local OS-authenticated user with s This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
cvelistv5nvd