Skip to main content

Vulnerabilities

During my work as a pentester, I was lucky to find some vulnerabilities in third-party software:

DateProductCVESeverityAdvisory
08/2025Weblication CMS CoreCVE-2025-52161Criticalusd-2025-0031
05/2025d.3one-Highusd-2025-0019
04/2022Apache Karaf1CVE-2021-41766Highusd-2021-0025
08/2021TIBCO ActiveMatrix BusinessWorks-Criticalusd-2021-0012
07/2021KeyCloak-Mediumusd-2021-0016
04/2020Userlike ChatCVE-2019-19214Lowusd-2019-0058
04/2020Userlike ChatCVE-2019-19213Criticalusd-2019-0057
12/2018SEP sesam2CVE-2018-7750Highusd-2018-0025

Footnotes

  1. 99% of the credit for this CVE goes to Tobias Neitzel, who understands JMX vulnerabilities like no other. He wrote beanshooter and even adapted it to work with Apache Karaf.

  2. 99% of the credit for this CVE goes to Daniel Hoffman, who discovered the underlying CVE-2018-1000805.