Data Center
Vendor:
First CVE: Sep 17, 2020 · Active for 5 years
39
Total CVEs
More Total CVEs than 97% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Data Center over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2020
5 years ago
Most Recent CVE
Feb 28, 2022
1,607 days ago
CVE Severity & Scoring
Data Center39 CVEs
79%
15%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network39 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None24 (61.5%)
Unknown0 (0.0%)
Required15 (38.5%)
Privileges Required
Low7 (17.9%)
High5 (12.8%)
None27 (69.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14181MEDIUM Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa e | Sep 17, 2020 | 5.3 | 88 | NO | YES |
CVE-2020-36289MEDIUM Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendere | May 12, 2021 | 5.3 | 80 | NO | YES |
CVE-2020-29453MEDIUM The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthentica | Feb 22, 2021 | 5.3 | 38 | NO | YES |
CVE-2021-26078MEDIUM The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16 | Jun 7, 2021 | 6.1 | 31 | NO | YES |
CVE-2017-18113HIGH The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malic | Aug 2, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-43947HIGH Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerab | Jan 6, 2022 | 7.2 | 25 | NO | NO |
CVE-2021-39123HIGH Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerabili | Sep 14, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-41312HIGH Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collect | Nov 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-39113HIGH Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Co | Aug 30, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-26070HIGH Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulner | Mar 22, 2021 | 7.2 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 96th percentile
Nuclei
3 CVEs
7.7% of CVEs· 97th percentile
ExploitDB
2 CVEs
5.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (39 CVEs).
Media Mentions
Signals from CVEs in this product scope (39 CVEs).
Top CNAs Publishing CVEs For Data Center
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8 | 1 | 5.3 | 1.4% | 0 | 0 |