Vulnerabilities (CVE)

Filtered by vendor M-files Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6239 1 M-files 1 M-files Server 2023-12-04 N/A 8.8 HIGH
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
CVE-2023-6117 1 M-files 1 M-files Server 2023-11-30 N/A 7.5 HIGH
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.
CVE-2021-37254 1 M-files 1 M-files Web 2022-07-12 5.0 MEDIUM 7.5 HIGH
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
CVE-2021-37253 1 M-files 1 M-files Web 2022-01-18 7.8 HIGH 7.5 HIGH
** DISPUTED ** M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application.