Team Foundation Server

Vendor:

First CVE: Nov 14, 2018 · Active for 7 years

23
Total CVEs
More Total CVEs than 95% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Team Foundation Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2018
7 years ago
Most Recent CVE
Apr 13, 2021
1,928 days ago

CVE Severity & Scoring

Team Foundation Server23 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None7 (30.4%)
Unknown0 (0.0%)
Required16 (69.6%)
Privileges Required
Low15 (65.2%)
High0 (0.0%)
None8 (34.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation
Sep 11, 20199.840NONO
A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Te
Nov 15, 20189.837NONO
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Se
Jul 15, 20199.835NONO
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to
May 16, 20196.525NONO
An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure V
Jan 17, 20196.524NONO
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Tea
Apr 9, 20196.122NONO
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulne
Sep 11, 20195.421NONO
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Tea
Apr 9, 20196.121NONO
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulne
Apr 9, 20195.421NONO
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulne
Mar 5, 20195.421NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Team Foundation Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2018236.33.7%00
2017156.22.8%00
201566.43.7%00
201319.812.4%00
201219.812.4%00
201019.812.4%00