Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Akamai/
  3. Akamai Enterprise Application Access

Akamai Enterprise Application Access

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 22 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

ZTNA solution providing identity-based access to private apps

by Akamai · akamai.com · source ↗

Known CVEs (22)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-34354 ↗HIGH 7.42026

    Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp director…

  • CVE-2026-26365 ↗MEDIUM 4.02026

    Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could…

  • CVE-2025-66373 ↗MEDIUM 4.82025

    Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that…

  • CVE-2025-53841 ↗HIGH 7.82025

    The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerabilit…

  • CVE-2025-54142 ↗MEDIUM 4.02025

    Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akama…

  • CVE-2025-32094 ↗MEDIUM 4.02025

    An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" …

  • CVE-2025-54568 ↗LOW 3.72025

    Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node.

  • CVE-2025-52491 ↗MEDIUM 5.82025

    Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

  • CVE-2025-49493 ↗MEDIUM 5.82025

    Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

  • CVE-2025-30143 ↗MEDIUM 5.42025

    Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.

  • CVE-2025-24527 ↗HIGH 8.02025

    An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.

  • CVE-2024-45164 ↗HIGH 7.12024

    Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorr…

  • CVE-2021-40683 ↗HIGH 7.82021

    In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.

  • CVE-2019-11011 ↗CRITICAL 9.82019

    Akamai CloudTest before 58.30 allows remote code execution.

  • CVE-2017-12256 ↗MEDIUM 6.52017

    A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on …

  • CVE-2016-10157 ↗CRITICAL 9.82017

    Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the insta…

  • CVE-2009-2582 ↗HIGH 9.32009

    Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R…

  • CVE-2008-1106 ↗HIGH 7.12008

    The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoo…

  • CVE-2008-1770 ↗HIGH 9.32008

    CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an …

  • CVE-2007-6339 ↗MEDIUM 6.82008

    The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified …

  • …and 2 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Secure Access Service Edge (SASE/SSE) products

see all →
  • 1Password Device Trust · 1Password
  • AWS Verified Access · Amazon Web Services, Inc.
  • Absolute Core · Absolute
  • Absolute Resilient, AI-powered SSE · Absolute
  • Agilicus · Agilicus
  • Akamai Secure Internet Access Enterprise · Akamai
  • Alibaba Cloud Secure Access Service Edge · Alibaba Cloud
  • Alkira Zero Trust Network Access · Alkira