Aveva Application Server vulnerabilities
4 known vulnerabilities affecting aveva/application_server.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4
Vulnerabilities
Page 1 of 1
CVE-2025-8386HIGHCVSS 7.2≤ Versions 2023 R2 SP1 P022025-11-15
CVE-2025-8386 [HIGH] CWE-80 CVE-2025-8386: The vulnerability, if exploited, could allow an authenticated miscreant
(with privilege of "aaConfi
The vulnerability, if exploited, could allow an authenticated miscreant
(with privilege of "aaConfigTools") to tamper with App Objects' help
files and persist a cross-site scripting (XSS) injection that when
executed by a victim user, can result in horizontal or vertical
escalation of privileges. The vulnerability can only be exploited during
config-time
cvelistv5nvd
CVE-2024-7113HIGHCVSS 8.7≤ 2023 R2 P012024-08-13
CVE-2024-7113 [HIGH] CWE-770 CVE-2024-7113: If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resource
If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.
cvelistv5nvd
CVE-2023-33873HIGHCVSS 7.8≤ 2020 R2 SP1 P012023-11-15
CVE-2023-33873 [HIGH] CWE-250 CVE-2023-33873:
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user wi
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
cvelistv5nvd
CVE-2023-34982HIGHCVSS 7.1≤ 2020 R2 SP1 P012023-11-15
CVE-2023-34982 [HIGH] CWE-73 CVE-2023-34982:
This external control vulnerability, if exploited, could allow a local OS-authenticated user with s
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
cvelistv5nvd