Security Advisories

Responsible disclosure of security vulnerabilities.

What does Security Advisories mean?

Nearly every information system has errors. These errors are being discovered throughout the lifespan of a system. If these errors affect the confidentiality, integrity or availability of a system, they are called security vulnerabilities.

Vulnerabilities found by the aramido GmbH are disclosed in a responsible way to the public according to the following procedure. Vulnerabilities for which customers of aramido are responsible or which are otherwise legally excluded from publication are not disclosed according to this policy.

After a security vulnerability is discovered, the responsible parties for the system or the application are informed in a confidential manner. The security advisory describes the type and exploitability of the vulnerability. The security advisory will be published after the vulnerability is patched or at least after 45 days after the first notice, regardless of the remediation level, on the aramido website. Exceptions to this process are only made in well justified cases and after considering the impact on the public.

Vulnerabilities found by aramido could have already been discovered and exploited by others. Therefore, vulnerabilities should immediately be patched. It is the social responsibility of aramido to protect the public and disclose vulnerabilities. This way vulnerabilities get fixed, everyone can learn from past mistakes and adjust his or her behavior.


All blog articles on the subject of Security Advisories
Moritz Kaumanns

Published on 01.02.2021 in the category Security Advisories published.

Security Advisory: Amazon Secret Key Publicly Accessible (CVE-2020-28199)

A security vulnerability in an Amazon Pay plugin for Shopware 5 allows the unauthorized reading of the Amazon Secret Key (CVE-2020-28199). (read more)

Andreas Sperber

Published on 14.09.2020 in the category Security Advisories published.

Security Advisory: 1CRM Insufficient Data Protection (CVE-2020-15958)

A security vulnerability in the 1CRM software allowed unauthorized users to access sensitive files and system backups. (read more)

Tristan Wagner

Published on 09.07.2020 in the category Security Advisories published.

Two Vulnerabilities in TeamBeam

aramido was able to identify two vulnerabilities in the data exchange platform TeamBeam. (read more)

Benjamin Pokrant

Published on 06.05.2020 in the category Security Advisories published.

HTML Injection Vulnerability in WordPress Plugin WPForms

A security vulnerability in the WordPress plugin WPForms allowed attacks via HTML injection. How does this vulnerability affect systems and how can it be closed? (read more)

Jonas Lehmann

Published on 03.04.2020 in the category Security Advisories published.

How can IT managers ensure a secure home office during the coronavirus pandemic?

A six-step guide for information security in the home office and tips for financial support. (read more)

Elisabeth Apicella

Published on 20.12.2018 in the category Security Advisories published.

Security Advisory: Three Findings at prescreen.io and jobbase.io

As aramido discovered, the cloud-based applicant management software of the company Prescreen had several security deficiencies. (read more)

Elisabeth Apicella

Published on 07.11.2018 in the category Security Advisories published.

Reflected HTML Injection in CRM Software

A security vulnerability in the web software CRM+ by Brainformatik allowed attacks via HTML injection. Who is affected and what should you do now? (read more)

Armin Harbrecht

Published on 03.03.2017 in the category Security Advisories published.

Multiple Vulnerabilities in the New CyberForum Portal

aramido found several security vulnerabilities on the CyberForum website. They show the typical dangers of websites with user-generated content. (read more)

Armin Harbrecht

Published on 06.02.2017 in the category Security Advisories published.

Security through Transparency – How We Disclose Security Vulnerabilities

The responsible disclosure of security vulnerabilities is a proven approach to making IT systems more secure for everyone. (read more)