📦 J2eefast

by J2eefast

🔍 What is J2eefast?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-45944

CRITICAL CVSS 9.8 Oct 18, 2024

This vulnerability in J2eeFAST allows attackers to bypass backend filtering mechanisms and execute arbitrary code on affected systems. It affects all users running J2eeFAST version 2.7 or earlier. The...

CVE-2024-35091

CRITICAL CVSS 9.8 May 23, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the findPage function within SysTenantMapper.xml. This allows attackers to execute arbitrary SQL commands on the database. All systems running...

CVE-2024-35084

CRITICAL CVSS 9.8 May 23, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the findPage function of SysMsgPushMapper.xml that allows attackers to execute arbitrary SQL commands. This affects all systems running the vu...

CVE-2024-35086

CRITICAL CVSS 9.8 May 23, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the findPage function of BpmTaskFromMapper.xml. This allows attackers to execute arbitrary SQL commands on the database. All systems running t...

CVE-2024-33164

CRITICAL CVSS 9.8 May 7, 2024

CVE-2024-33164 is a critical SQL injection vulnerability in J2EEFAST v2.7.0 that allows attackers to execute arbitrary SQL commands via the sql_filter parameter in the authUserList() function. This af...

CVE-2024-33153

CRITICAL CVSS 9.8 May 7, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the commentList() function via the sql_filter parameter. This allows attackers to execute arbitrary SQL commands on the database. All deployme...

CVE-2024-33146

CRITICAL CVSS 9.1 May 7, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the export function's sql_filter parameter. This allows attackers to execute arbitrary SQL commands on the database. Organizations using J2EEF...

CVE-2021-28890

CRITICAL CVSS 9.8 Aug 12, 2021

CVE-2021-28890 is a critical SQL injection vulnerability in J2eeFAST that allows remote attackers to execute arbitrary SQL commands via specific parameters. This affects J2eeFAST 2.2.1 installations a...

CVE-2024-35083

HIGH CVSS 8.8 May 23, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the findPage function of SysLoginInfoMapper.xml. This allows attackers to execute arbitrary SQL commands on the database. All systems running ...

CVE-2024-33147

HIGH CVSS 8.8 May 7, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the authRoleList function's sql_filter parameter. This allows attackers to execute arbitrary SQL commands on the database. Organizations using...

CVE-2024-33149

HIGH CVSS 8.1 May 7, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the sql_filter parameter of the myProcessList function. This allows attackers to execute arbitrary SQL commands on the database. Organizations...

CVE-2024-33139

HIGH CVSS 7.5 May 7, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the sql_filter parameter of the findpage function. This allows attackers to execute arbitrary SQL commands on the database. Organizations usin...

CVE-2024-35082

MEDIUM CVSS 6.3 May 23, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the SysOperLogMapper.xml file's findPage function. This allows attackers to execute arbitrary SQL commands on the database. Organizations usin...

CVE-2024-33161

MEDIUM CVSS 5.3 May 7, 2024

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the unallocatedList() function via the sql_filter parameter. This allows attackers to execute arbitrary SQL commands on the database. Organiza...