VendorsPTCthingworx_platformall versions
Vulnerabilities

PTC ThingWorx Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2018-20092
PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.
Published 2018-12-17 · Modified
7.5EPSS 0.022
CVE-2018-17217
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.
Published 2018-10-01 · Modified
7.5EPSS 0.008
CVE-2018-17216
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.
Published 2018-10-01 · Modified
6.5EPSS 0.011
CVE-2018-17218
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function.
Published 2018-10-01 · Modified
5.4EPSS 0.006