VendorsKNIMEknime_serverall versions
Vulnerabilities

KNIME KNIME Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-44726
KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
Published 2021-12-08 · Modified
8.8EPSS 0.007
CVE-2021-44725
KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.
Published 2021-12-08 · Modified
7.5EPSS 0.015
CVE-2022-44748
Uploading workflows to KNIME Server may override arbitrary file system contents
Published 2022-11-24 · Modified
7.5EPSS 0.014
CVE-2021-45097
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.
Published 2021-12-16 · Modified
5.5EPSS 0.002