Banking Extensibility Workbench

Vendor:

First CVE: Jul 26, 2019 · Active for 7 years

20
Total CVEs
More Total CVEs than 95% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Banking Extensibility Workbench over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2019
7 years ago
Most Recent CVE
Feb 15, 2021
1,989 days ago

CVE Severity & Scoring

Banking Extensibility Workbench20 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (30.0%)
High14 (70.0%)
Unknown0 (0.0%)
User Interaction
None19 (95.0%)
Unknown0 (0.0%)
Required1 (5.0%)
Privileges Required
Low1 (5.0%)
High1 (5.0%)
None18 (90.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Feb 15, 20217.248NOYES
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDICo
Dec 27, 20208.131NONO
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype usin
Jul 26, 20199.131NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDICo
Jan 6, 20218.130NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolD
Jan 6, 20218.130NONO
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, all
Dec 18, 20208.130NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPD
Jan 7, 20218.128NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDat
Jan 6, 20218.128NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDa
Jan 6, 20218.128NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDa
Jan 6, 20218.128NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Banking Extensibility Workbench

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.5.047.010.3%01
14.5118.26.5%00
14.4.058.25.3%00
14.3.097.77.5%01
14.3118.26.5%00
14.2.047.010.3%01
14.2118.26.5%00