Ehealth Performance Manager
4 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Ehealth Performance Manager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Ehealth Performance Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 4 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High2
- Medium1
- Low1
Latest CVEs
The 4 most recently published vulnerabilities affecting Ehealth Performance Manager.
- CVE-2021-28250CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the sc...7.8
- CVE-2021-28249CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a mali...8.8
- CVE-2021-28247CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrec...5.4
- CVE-2010-0640Cross-site scripting (XSS) vulnerability in CA eHealth Performance Manager 6.0.x through 6.2.x, when malicious HTML detection is disabled, allows remote attackers to inject arbitrary web script or ...2.6
Product grouping is registry-driven, with AI assist and human review. How it works