Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2020-6937
Disclosure Date: May 29, 2020 (last updated November 27, 2024)
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
0
Attacker Value
Unknown
CVE-2020-10991
Disclosure Date: March 27, 2020 (last updated February 21, 2025)
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
0
Attacker Value
Unknown
CVE-2019-15631
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-13116
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
0
Attacker Value
Unknown
CVE-2019-15630
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.
0
Attacker Value
Unknown
CVE-2014-9000
Disclosure Date: November 20, 2014 (last updated October 05, 2023)
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.
0