Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Elastic/
  3. Elastic Workflows for Security

Elastic Workflows for Security

SOARAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 68 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~46 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Automate alert triage, enrichment, and response natively (no separate SOAR).

by Elastic · elastic.co · source ↗

Known CVEs (68)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2019-7618 ↗MEDIUM 6.52019

    A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local file…

  • CVE-2019-7617 ↗HIGH 7.22019

    When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attac…

  • CVE-2019-7885 ↗HIGH 8.82019

    Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.…

  • CVE-2019-7615 ↗HIGH 7.42019

    A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would …

  • CVE-2019-1867 ↗CRITICAL 10.02019

    A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to imprope…

  • CVE-2019-1003052 ↗HIGH 8.82019

    Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sy…

  • CVE-2018-3164 ↗MEDIUM 6.12018

    Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Elastic Search). Supported versions that are affected are 8.55 and 8.56. Easily exploitabl…

  • CVE-2018-3829 ↗MEDIUM 5.32018

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous run…

  • CVE-2018-3828 ↗HIGH 7.52018

    Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, an…

  • CVE-2018-3825 ↗MEDIUM 5.92018

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, …

  • CVE-2016-0715 ↗MEDIUM 5.92018

    Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote information disclosure. It was found that original mitigation…

  • CVE-2018-0130 ↗CRITICAL 9.82018

    A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative acces…

  • CVE-2018-0121 ↗CRITICAL 9.82018

    A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authenticati…

  • CVE-2018-0106 ↗LOW 3.32018

    A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerabilit…

  • CVE-2015-5173 ↗HIGH 8.82017

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with…

  • CVE-2015-5172 ↗CRITICAL 9.82017

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire p…

  • CVE-2015-5171 ↗CRITICAL 9.82017

    The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified imp…

  • CVE-2015-5170 ↗HIGH 8.82017

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks …

  • CVE-2017-10335 ↗HIGH 7.52017

    Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Elastic Search). Supported versions that are affected are 8.55 and 8.56. Easily exploit…

  • CVE-2017-8021 ↗CRITICAL 9.82017

    EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system.

  • …and 48 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Security Orchestration, Automation & Response (SOAR) products

see all →
  • 7AI Platform · 7AI
  • AI EdgeLabs AI-Generated Playbooks · AI EdgeLabs
  • AIStrike BlueDome · AiStrike
  • ASPIA Infotech Security Workflow · ASPIA Infotech Pvt. Ltd.
  • Abusix Guardian Ops · Abusix
  • Agentic AI AR2™ · BluSapphire Cyber Systems Pvt Limited
  • Agentic Security Automation Platform · Blink Ops
  • Agents · Tines