Service Manager
Vendor:
First CVE: Oct 20, 2022 · Active for 3 years
5
Total CVEs
More Total CVEs than 79% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Service Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2022
3 years ago
Most Recent CVE
Jan 10, 2023
1,295 days ago
CVE Severity & Scoring
Service Manager5 CVEs
40%
60%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low4 (80.0%)
High0 (0.0%)
None1 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38490HIGH An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue. | Jan 10, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-38492HIGH An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability. | Jan 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-38491HIGH An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corre | Jan 10, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-33231MEDIUM Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field. | Oct 20, 2022 | 5.4 | 23 | NO | NO |
CVE-2022-38489MEDIUM An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably. | Jan 10, 2023 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Service Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2022.1.109.0.03 | 4 | 7.6 | 0.6% | 0 | 0 |
| 2020.2.125.3 | 4 | 7.6 | 0.6% | 0 | 0 |
| 2018.1.181.1 | 1 | 5.4 | 0.5% | 0 | 0 |