Banking Payments
Vendor:
First CVE: Jan 18, 2018 · Active for 8 years
35
Total CVEs
More Total CVEs than 97% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Banking Payments over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2018
8 years ago
Most Recent CVE
Apr 18, 2023
1,197 days ago
CVE Severity & Scoring
Banking Payments35 CVEs
69%
29%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.9%)
Network34 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (85.7%)
High5 (14.3%)
Unknown0 (0.0%)
User Interaction
None27 (77.1%)
Unknown0 (0.0%)
Required8 (22.9%)
Privileges Required
Low22 (62.9%)
High0 (0.0%)
None13 (37.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2019-13990CRITICAL initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | Jul 26, 2019 | 9.8 | 40 | NO | NO |
CVE-2019-12402HIGH The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a | Aug 30, 2019 | 7.5 | 33 | NO | NO |
CVE-2021-36090HIGH When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 31 | NO | NO |
CVE-2021-35515HIGH When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35517HIGH When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 29 | NO | NO |
CVE-2019-12399HIGH When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that | Jan 14, 2020 | 7.5 | 26 | NO | NO |
CVE-2018-2705HIGH Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and | Jan 18, 2018 | 8.8 | 25 | NO | NO |
CVE-2021-41973MEDIUM In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginn | Nov 1, 2021 | 6.5 | 24 | NO | NO |
CVE-2021-30129MEDIUM A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of | Jul 12, 2021 | 6.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Banking Payments
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 14.7 | 1 | 4.6 | 0.4% | 0 | 0 |
| 14.6 | 1 | 4.6 | 0.4% | 0 | 0 |
| 14.5 | 8 | 6.5 | 18.0% | 0 | 0 |
| 14.4.0 | 1 | 7.5 | 3.9% | 0 | 0 |
| 14.1.0 | 10 | 5.9 | 1.6% | 0 | 0 |
| 14.0.0 | 5 | 6.1 | 1.4% | 0 | 0 |
| 12.5.0 | 13 | 6.1 | 1.6% | 0 | 0 |
| 12.4.0 | 16 | 6.3 | 1.6% | 0 | 0 |
| 12.3.0 | 16 | 6.3 | 1.6% | 0 | 0 |
| 12.2.0 | 9 | 6.0 | 1.7% | 0 | 0 |