Vulnerabilities (CVE)

Filtered by vendor Osisoft Subscribe
Filtered by product Pi Web Api
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43549 1 Osisoft 1 Pi Web Api 2021-11-23 3.5 LOW 4.8 MEDIUM
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.
CVE-2019-13515 1 Osisoft 1 Pi Web Api 2019-10-09 4.0 MEDIUM 6.5 MEDIUM
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
CVE-2018-7508 1 Osisoft 2 Pi Vision, Pi Web Api 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectly neutralized.