Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Openmeetings
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7673 1 Apache 1 Openmeetings 2019-10-03 5.0 MEDIUM 9.8 CRITICAL
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
CVE-2016-8736 1 Apache 1 Openmeetings 2019-03-01 7.5 HIGH 9.8 CRITICAL
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
CVE-2017-7664 1 Apache 1 Openmeetings 2017-07-19 7.5 HIGH 10.0 CRITICAL
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.