Communications Cloud Native Core Policy
Vendor:
First CVE: Jun 16, 2017 · Active for 9 years
125
Total CVEs
More Total CVEs than 99% of tracked products
20.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Communications Cloud Native Core Policy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2017
9 years ago
Most Recent CVE
Apr 18, 2023
1,197 days ago
CVE Severity & Scoring
Communications Cloud Native Core Policy125 CVEs
38%
53%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (22.4%)
Network93 (74.4%)
Unknown0 (0.0%)
Physical2 (1.6%)
Adjacent Network2 (1.6%)
Attack Complexity
Low70 (56.0%)
High55 (44.0%)
Unknown0 (0.0%)
User Interaction
None113 (90.4%)
Unknown0 (0.0%)
Required12 (9.6%)
Privileges Required
Low44 (35.2%)
High5 (4.0%)
None76 (60.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (125 CVEs).
125 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22963CRITICAL In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r | Apr 1, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-22965CRITICAL A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run | Apr 1, 2022 | 9.8 | 98 | YES | YES |
CVE-2021-39144HIGH XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute command | Aug 23, 2021 | 8.5 | 98 | YES | YES |
CVE-2019-3799MEDIUM Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arb | May 6, 2019 | 6.5 | 88 | NO | YES |
CVE-2020-13935HIGH The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl | Jul 14, 2020 | 7.5 | 77 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2021-28169MEDIUM For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB | Jun 9, 2021 | 5.3 | 74 | NO | YES |
CVE-2020-5398HIGH In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R | Jan 17, 2020 | 7.5 | 73 | NO | NO |
CVE-2021-42392CRITICAL The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name | Jan 10, 2022 | 9.8 | 68 | NO | NO |
CVE-2020-9484HIGH When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f | May 20, 2020 | 7.0 | 66 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (125 CVEs).
CISA KEV
3 CVEs
2.4% of CVEs· 98th percentile
Metasploit
4 CVEs
3.2% of CVEs· 97th percentile
Nuclei
11 CVEs
8.8% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.6% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (125 CVEs).
Media Mentions
Signals from CVEs in this product scope (125 CVEs).
Top CNAs Publishing CVEs For Communications Cloud Native Core Policy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 23.1.0 | 1 | 5.3 | 1.3% | 0 | 0 |
| 22.4.0 | 1 | 5.3 | 1.3% | 0 | 0 |
| 22.3.0 | 1 | 4.4 | 0.2% | 0 | 0 |
| 22.2.0 | 27 | 6.2 | 1.7% | 0 | 0 |
| 22.1.3 | 3 | 6.9 | 34.4% | 1 | 1 |
| 22.1.0 | 2 | 9.8 | 99.8% | 2 | 2 |
| 1.9.0 | 2 | 7.4 | 16.8% | 0 | 0 |
| 1.5.0 | 3 | 7.0 | 32.6% | 0 | 0 |
| 1.15.0 | 22 | 6.7 | 25.5% | 2 | 3 |
| 1.14.0 | 65 | 7.5 | 13.0% | 1 | 7 |
| 1.11.0 | 3 | 6.6 | 11.3% | 0 | 1 |