Apm Agent

Vendor:

First CVE: Aug 22, 2019 · Active for 6 years

3
Total CVEs
More Total CVEs than 64% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Apm Agent over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2019
6 years ago
Most Recent CVE
Dec 8, 2021
1,689 days ago

CVE Severity & Scoring

Apm Agent3 CVEs
All CVEs352,231 CVEs
LowHigh
Attack Vector
Local1 (33.3%)
Network1 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (33.3%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (33.3%)
High1 (33.3%)
None1 (33.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Us
Dec 8, 20217.825NONO
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This coul
Aug 22, 20197.219NONO
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sa
Feb 10, 20212.413NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Apm Agent

Top CWEs

Versions

No cataloged versions.