Security Advisories
Cyber Security
Security Advisories
As soon as an actively exploited vulnerability in one of our products has been confirmed and a corrective measure or mitigation is available, we publish a security advisory. Every advisory contains:
- the unique advisory ID (SAYYYYNNN) and the document revision
- the affected products, article numbers and versions
- the assigned CVE ID and the vulnerability class (CWE)
- a severity rating in accordance with CVSS v4.0, including the vector
- the impact in the application: what an attacker could achieve, and under which conditions
- the remediation: security update, patch, workaround or compensating measure, with concrete steps to take
Advisories are updated and versioned as new findings emerge. All advisories remain permanently available, including after the end of a product’s support period.
Where we can foresee that publication would, in the short term, put users at greater risk than it protects them, we withhold the level of detail until a security update is available or can be rolled out. Even in that case, we will still inform you that an issue exists and about any immediate measures to take.
| Date | Advisory Titel | ID | Revision | LINK PDF | LINK CSAF |
|---|---|---|---|---|---|