Banking Apis
Vendor:
First CVE: Oct 10, 2019 · Active for 6 years
14
Total CVEs
More Total CVEs than 92% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Banking Apis over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2019
6 years ago
Most Recent CVE
Nov 17, 2021
1,714 days ago
CVE Severity & Scoring
Banking Apis14 CVEs
36%
50%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High2 (14.3%)
Unknown0 (0.0%)
User Interaction
None10 (71.4%)
Unknown0 (0.0%)
Required4 (28.6%)
Privileges Required
Low2 (14.3%)
High1 (7.1%)
None11 (78.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28164MEDIUM In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi | Apr 1, 2021 | 5.3 | 86 | NO | YES |
CVE-2020-25649HIGH A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi | Dec 3, 2020 | 7.5 | 34 | NO | NO |
CVE-2019-17495CRITICAL A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input f | Oct 10, 2019 | 9.8 | 33 | NO | NO |
CVE-2021-36090HIGH When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 31 | NO | NO |
CVE-2021-35517HIGH When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 29 | NO | NO |
CVE-2021-2351HIGH Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulne | Jul 21, 2021 | 8.3 | 28 | NO | NO |
CVE-2020-11987HIGH Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could | Feb 24, 2021 | 8.2 | 28 | NO | NO |
CVE-2021-37137HIGH The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the who | Oct 19, 2021 | 7.5 | 27 | NO | NO |
CVE-2021-37136HIGH The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All | Oct 19, 2021 | 7.5 | 27 | NO | NO |
CVE-2021-29425MEDIUM In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, | Apr 13, 2021 | 4.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
1 CVE
7.1% of CVEs· 97th percentile
ExploitDB
1 CVE
7.1% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Banking Apis
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 21.1 | 14 | 6.7 | 12.6% | 0 | 1 |
| 20.1 | 14 | 6.7 | 12.6% | 0 | 1 |
| 19.2 | 12 | 7.1 | 7.5% | 0 | 0 |
| 19.1 | 12 | 7.1 | 7.5% | 0 | 0 |
| 18.3 | 3 | 6.4 | 8.7% | 0 | 0 |
| 18.2 | 2 | 5.5 | 6.2% | 0 | 0 |
| 18.1 | 2 | 5.5 | 6.2% | 0 | 0 |