Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Tufin/
  3. Tufin Orchestration Suite

Tufin Orchestration Suite

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 9 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Network security policy orchestration and automation platform

by Tufin · tufin.com · source ↗

Known CVEs (9)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2020-13462 ↗MEDIUM 5.72021

    Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.

  • CVE-2020-13461 ↗MEDIUM 4.32021

    Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access …

  • CVE-2020-13460 ↗HIGH 8.82021

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.

  • CVE-2020-13409 ↗MEDIUM 5.92021

    Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or a…

  • CVE-2020-13408 ↗MEDIUM 5.92021

    Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or a…

  • CVE-2020-13407 ↗MEDIUM 5.92021

    Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or a…

  • CVE-2020-13134 ↗MEDIUM 4.82021

    Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be trigge…

  • CVE-2020-13133 ↗MEDIUM 6.12021

    Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be trigge…

  • CVE-2018-18406 ↗CRITICAL 9.92019

    An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using …

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Network Firewall (NGFW) products

see all →
  • AhnLab Network PLUS · AhnLab
  • Akamai Guardicore Segmentation · Akamai
  • Albarius · Albarius
  • AlgoSec AlgoBot · AlgoSec
  • AlgoSec Firewall Analyzer · AlgoSec
  • Allot Secure · Allot
  • Array ASI SSL Intercept · Array Networks
  • Barracuda Network Protection · Barracuda