VendorsKNIMEknime_analytics_platformany version
Vulnerabilities

KNIME Knime Analytics Platform any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-31500
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
Published 2022-05-31 · Modified
7.8EPSS 0.002
CVE-2022-44749
Opening workflows from untrusted resources may override arbitrary file system contents
Published 2022-11-24 · Modified
7.0EPSS 0.004
CVE-2023-5562
Unsafe default allows for cross-site scripting attacks in KNIME Server and KNIME Business Hub
Published 2023-10-12 · Modified
6.1EPSS 0.003
CVE-2021-45096
KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.
Published 2021-12-16 · Modified
4.7EPSS 0.011