threat
engine
.sh
Back
·
··:··
Home
/
Product
/
tangro business workflow
Product
tangro business workflow
9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-34689
all versions
WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal
5.0
MEDIUM
CVE-2020-26178
< 1.18.1
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being
5.3
MEDIUM
CVE-2020-26177
< 1.18.1
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to b
4.3
MEDIUM
CVE-2020-26176
< 1.18.1
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document
4.3
MEDIUM
CVE-2020-26175
< 1.18.1
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to
6.5
MEDIUM
CVE-2020-26174
< 1.18.1
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes
8.8
HIGH
CVE-2020-26173
< 1.18.1
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF
3.1
LOW
CVE-2020-26172
< 1.18.1
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token wh
4.2
MEDIUM
CVE-2020-26171
< 1.18.1
In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipul
4.3
MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin