Vendorssmeuperpall versions
Vulnerabilities

smeup erp TOKYO V6R1M230915

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-26759
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component.
Published 2023-02-27 · Modified
8.8EPSS 0.024
CVE-2023-26762
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability.
Published 2023-02-27 · Modified
8.8EPSS 0.010
CVE-2023-26758
Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.
Published 2023-02-27 · Modified
7.5EPSS 0.009
CVE-2023-26760
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.
Published 2023-02-27 · Modified
7.5EPSS 0.005