Flexera Flexera

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Flexera product.

RSS Feeds for Flexera security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Flexera products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Flexera Sorted by Most Security Vulnerabilities since 2018

Flexera Flexnet Publisher10 vulnerabilities

Flexera Flexnet Code Insight2 vulnerabilities

Flexera Installshield2 vulnerabilities

Flexera Flexnet Manager1 vulnerability

By the Year

In 2026 there have been 1 vulnerability in Flexera with an average score of 4.0 out of ten. Last year, in 2025 Flexera had 1 security vulnerability published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Flexera in 2026 could surpass last years number.




Year Vulnerabilities Average Score
2026 1 4.00
2025 1 0.00
2024 1 5.50
2023 3 7.70
2022 0 0.00
2021 4 5.50
2020 2 0.00
2019 4 0.00

It may take a day or so for new Flexera vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Flexera Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2019-25313 Feb 11, 2026
FlexNet 11.12.1 XSRF creates admin accounts without authentication FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.
Flexnet Publisher
CVE-2024-2658 Jan 30, 2025
FlexNet Publisher lmadmin.exe Exec via OpenSSL config (before 11.19.6.0) A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.
Flexnet Publisher
CVE-2023-29081 Jan 26, 2024
InstallShield <2023 R2 Local Auth DoS via Temp Folder Move A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.
Installshield
CVE-2019-8963 Mar 29, 2023
FlexNet Publisher lmadmin 11.16.5 DoS via crafted POST request A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.
Flexnet Publisher
CVE-2021-41526 Mar 29, 2023
Privilege Escalation in Windows MSI via InstallScript CA A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked repair of the MSI which has an InstallScript custom action.
Revenera Installshield
CVE-2017-6894 Mar 29, 2023
Local Privilege Escalation in FlexNet Manager Suite 2015 R2 SP3 (FlexNet Platform 9.2) A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system.
Flexnet Manager
Flexnet Manager Suite 2015
CVE-2021-41525 Sep 21, 2021
An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior. An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior.
Flexnet Inventory Agent Beacon
CVE-2020-12082 Sep 17, 2021
A stored cross-site scripting issue impacts certain areas of the Web UI for Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64). A stored cross-site scripting issue impacts certain areas of the Web UI for Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).
Flexnet Code Insight
CVE-2020-12080 Sep 17, 2021
A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6 A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.
Flexnet Publisher
CVE-2020-12083 Sep 17, 2021
An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64). An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).
Flexnet Code Insight
CVE-2019-8961 Apr 21, 2020
A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2 A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can repeatedly send messages of that type to cause a stack exhaustion condition.
Flexnet Publisher
CVE-2019-8960 Apr 21, 2020
A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2 A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message, but no second message received, the function eventually return an unexpected value which leads to an exception being thrown. The end result can be process termination.
Flexnet Publisher
CVE-2018-20034 Mar 21, 2019
A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
Flexnet Publisher
CVE-2018-20032 Mar 21, 2019
A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
Flexnet Publisher
CVE-2018-20031 Mar 21, 2019
A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
Flexnet Publisher
CVE-2018-20033 Feb 25, 2019
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.
Flexnet Publisher
CVE-2016-2542 Feb 24, 2016
Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.
Installshield
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.