Browse all 7 CVE security advisories affecting Aternity. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Aternity provides digital experience monitoring for enterprise endpoints, analyzing user interactions to optimize performance. Historically, vulnerabilities have included cross-site scripting (XSS), remote code execution (RCE), and privilege escalation flaws, often stemming from input validation failures and insecure default configurations. The platform's extensive system access increases potential impact, with seven CVEs recorded to date. While no major public incidents have been widely reported, the nature of its system-level privileges means successful exploitation could lead to comprehensive network compromise. Regular security updates and proper hardening remain critical for organizations using this monitoring solution.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-42854 | Directory Traversal Read/Write/Delete at PluginServlet — SteelCentral AppInternals Dynamic Sampling Agent CWE-20 | 9.8 | Critical | 2022-03-09 |
| CVE-2021-42856 | Reflected Cross-site Scripting at DsaDataTest — SteelCentral AppInternals Dynamic Sampling Agent CWE-20 | 4.7 | Medium | 2022-03-09 |
| CVE-2021-42787 | Directory Traversal Write/Delete/Partial Read at AgentConfigurationServlet — SteelCentral AppInternals Dynamic Sampling Agent CWE-20 | 9.4 | Critical | 2022-03-09 |
| CVE-2021-42857 | Directory Traversal Partial Write at AgentDaServlet — SteelCentral AppInternals Dynamic Sampling Agent CWE-20 | 5.3 | Medium | 2022-03-09 |
| CVE-2021-42855 | Local privilege escalation due to misconfigured write permission on .debug_command.config file — SteelCentral AppInternals Dynamic Sampling Agent CWE-284 | 7.8 | High | 2022-03-09 |
| CVE-2021-42786 | Remote Code Execution at AgentControllerServlet — SteelCentral AppInternals Dynamic Sampling Agent CWE-20 | 9.8 | Critical | 2022-03-09 |
| CVE-2021-42853 | Directory Traversal Delete/Read at AgentDiagnosticServlet — SteelCentral AppInternals Dynamic Sampling Agent CWE-20 | 9.1 | Critical | 2022-03-09 |
This page lists every published CVE security advisory associated with Aternity. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.