Genesys
3 CVEs tracked since 2021. Since Dec 2021, none of them reached CISA KEV.
Genesys CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-12 | 3 | 0 |
Products
The products that kept showing up in Genesys's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 7 most recently published vulnerabilities affecting Genesys.
- CVE-2023-23208Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.6.1
- CVE-2023-29930An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.8.8
- CVE-2022-37775Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.6.1
- CVE-2021-26787A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.6.1
- CVE-2021-40861A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with ...7.2
- CVE-2021-40860A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression p...7.2
- CVE-2019-17176Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).6.1
The record
- Peak rank
- #164 in Dec 2021
- Busiest month shown
- Dec 2021, 3 CVEs
- Months with a KEV entry
- 0 since Dec 2021
- Monthly snapshots
- 1 since 2021