Banco
Vendor:
First CVE: Aug 3, 2018 · Active for 7 years
6
Total CVEs
More Total CVEs than 83% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Banco over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2018
7 years ago
Most Recent CVE
Aug 3, 2018
2,916 days ago
CVE Severity & Scoring
Banco6 CVEs
50%
33%
17%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14925CRITICAL Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components. | Aug 3, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-14926HIGH Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request. | Aug 3, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-14928HIGH /contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter. | Aug 3, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-14929MEDIUM Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter. | Aug 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-14924MEDIUM Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field. | Aug 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-14927MEDIUM Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application folder) via the /contingency/servlet/ServletFileDownload file pa | Aug 3, 2018 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Banco
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.0 | 6 | 7.3 | 1.1% | 0 | 0 |