7 Mode Transition Tool
Vendor:
First CVE: Apr 6, 2017 · Active for 9 years
75
Total CVEs
More Total CVEs than 99% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
2.7%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact 7 Mode Transition Tool over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2017
9 years ago
Most Recent CVE
Jul 18, 2023
1,105 days ago
CVE Severity & Scoring
7 Mode Transition Tool75 CVEs
33%
49%
16%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.3%)
Network74 (98.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (48.0%)
High39 (52.0%)
Unknown0 (0.0%)
User Interaction
None66 (88.0%)
Unknown0 (0.0%)
Required9 (12.0%)
Privileges Required
Low1 (1.3%)
High0 (0.0%)
None74 (98.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (75 CVEs).
75 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12615HIGH When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upl | Sep 19, 2017 | 8.1 | 98 | YES | YES |
CVE-2016-8735CRITICAL Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener | Apr 6, 2017 | 9.8 | 97 | YES | YES |
CVE-2022-34169HIGH The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated b | Jul 19, 2022 | 7.5 | 70 | NO | NO |
CVE-2023-28709HIGH The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector set | May 22, 2023 | 7.5 | 52 | NO | NO |
CVE-2022-21449HIGH Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17 | Apr 19, 2022 | 7.5 | 52 | NO | NO |
CVE-2020-14593HIGH Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE | Jul 15, 2020 | 7.4 | 26 | NO | NO |
CVE-2016-1000338HIGH In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the s | Jun 1, 2018 | 7.5 | 24 | NO | NO |
CVE-2022-21299MEDIUM Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, | Jan 19, 2022 | 5.3 | 23 | NO | NO |
CVE-2022-21293MEDIUM Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u | Jan 19, 2022 | 5.3 | 23 | NO | NO |
CVE-2020-2803HIGH Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java | Apr 15, 2020 | 8.3 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (75 CVEs).
CISA KEV
2 CVEs
2.7% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.7% of CVEs· 96th percentile
ExploitDB
1 CVE
1.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (75 CVEs).
Media Mentions
Signals from CVEs in this product scope (75 CVEs).
Top CNAs Publishing CVEs For 7 Mode Transition Tool
Top CWEs
Versions
No cataloged versions.