Banking Payments

Vendor:

First CVE: Jan 18, 2018 · Active for 8 years

35
Total CVEs
More Total CVEs than 97% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Banking Payments over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2018
8 years ago
Most Recent CVE
Apr 18, 2023
1,197 days ago

CVE Severity & Scoring

Banking Payments35 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (2.9%)
Network34 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (85.7%)
High5 (14.3%)
Unknown0 (0.0%)
User Interaction
None27 (77.1%)
Unknown0 (0.0%)
Required8 (22.9%)
Privileges Required
Low22 (62.9%)
High0 (0.0%)
None13 (37.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Jul 26, 20199.840NONO
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a
Aug 30, 20197.533NONO
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.531NONO
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of
Jul 13, 20217.530NONO
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.529NONO
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that
Jan 14, 20207.526NONO
Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and
Jan 18, 20188.825NONO
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginn
Nov 1, 20216.524NONO
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of
Jul 12, 20216.524NONO

Exploit Exposure

Signals from CVEs in this product scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (35 CVEs).

Media Mentions

Signals from CVEs in this product scope (35 CVEs).

Top CNAs Publishing CVEs For Banking Payments

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.714.60.4%00
14.614.60.4%00
14.586.518.0%00
14.4.017.53.9%00
14.1.0105.91.6%00
14.0.056.11.4%00
12.5.0136.11.6%00
12.4.0166.31.6%00
12.3.0166.31.6%00
12.2.096.01.7%00