Comparison Overview
haifin, an e& enterprise company

haifin, an e& enterprise company
undefined, Dubai, undefined, undefined, AE
Last Update: 19/12/2025
Recognizing the importance of collaboration, visionaries from leading banks in the UAE partnered with e& (formerly Etisalat Group) to establish UAE Trade Connect in 2021, now known as haifin. This initiative aimed to combat trade finance fraud by leveraging innovative t...

Cholamandalam Investment and Finance Company Limited
Chola Crest, C54-55 & Super B-4, Thiru-Vi-Ka Industrial Estate, Guindy,, Chennai, Tamil Nadu, IN, 600032
Last Update: 02/04/2026
Cholamandalam Investment and Finance Company Limited (Chola), founded in 1978 as part of the Murugappa Group, initially focused on equipment financing. Over the years, Chola has transformed into a leading comprehensive financial services provider, offering a wide array ...
Compliance Ranges Comparison

haifin, an e& enterprise company







Cholamandalam Investment and Finance Company Limited






Benchmark & Cyber Underwriting Signals
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for haifin, an e& enterprise company in 2026.
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for Cholamandalam Investment and Finance Company Limited in 2026.
Incident History - haifin, an e& enterprise company (X = Date, Y = Severity)
haifin, an e& enterprise company cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Cholamandalam Investment and Finance Company Limited (X = Date, Y = Severity)
Cholamandalam Investment and Finance Company Limited cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

haifin, an e& enterprise company

Cholamandalam Investment and Finance Company Limited
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.