cbcvebase.

Sage X3 vulnerabilities

5 known vulnerabilities affecting sage/x3.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2020-7387P3MEDIUMCVSS 5.3PoC≥ 93.2.53, < AdxAdmin 93.2.532021-07-22
CVE-2020-7387 [MEDIUM] CWE-200 CVE-2020-7387: Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. Note that this vulnerability can be combined with CVE-2020-7388 to achieve full RCE. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions
nvd
CVE-2020-7389P3HIGHCVSS 7.2≥ V9, < Syracuse 9.22.7.2≥ V11, < Syracuse 11.25.2.6+1 more2021-07-22
CVE-2020-7389 [HIGH] CWE-306 CVE-2020-7389: Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
nvd
CVE-2023-31867P3HIGHCVSS 7.2v12.14.0.50-02023-06-22
CVE-2023-31867 [HIGH] CWE-1236 CVE-2023-31867: Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection. Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
nvd
CVE-2020-7390P4MEDIUMCVSS 5.4≥ V12, < Syracuse 12.10.02021-07-22
CVE-2020-7390 [MEDIUM] CWE-79 CVE-2020-7390: Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions o
nvd
CVE-2023-31868P4MEDIUMCVSS 5.4v12.14.0.50-02023-06-22
CVE-2023-31868 [MEDIUM] CWE-79 CVE-2023-31868: Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web appl Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by th
nvd
Sage X3 vulnerabilities | cvebase