Communications Cloud Native Core Policy

Vendor:

First CVE: Jun 16, 2017 · Active for 9 years

125
Total CVEs
More Total CVEs than 99% of tracked products
20.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Communications Cloud Native Core Policy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2017
9 years ago
Most Recent CVE
Apr 18, 2023
1,197 days ago

CVE Severity & Scoring

Communications Cloud Native Core Policy125 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local28 (22.4%)
Network93 (74.4%)
Unknown0 (0.0%)
Physical2 (1.6%)
Adjacent Network2 (1.6%)
Attack Complexity
Low70 (56.0%)
High55 (44.0%)
Unknown0 (0.0%)
User Interaction
None113 (90.4%)
Unknown0 (0.0%)
Required12 (9.6%)
Privileges Required
Low44 (35.2%)
High5 (4.0%)
None76 (60.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (125 CVEs).

125 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r
Apr 1, 20229.899YESYES
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run
Apr 1, 20229.898YESYES
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute command
Aug 23, 20218.598YESYES
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arb
May 6, 20196.588NOYES
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB
Jun 9, 20215.374NOYES
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name
Jan 10, 20229.868NONO
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f
May 20, 20207.066NOYES

Exploit Exposure

Signals from CVEs in this product scope (125 CVEs).

CISA KEV
3 CVEs
2.4% of CVEs· 98th percentile
Metasploit
4 CVEs
3.2% of CVEs· 97th percentile
Nuclei
11 CVEs
8.8% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.6% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (125 CVEs).

Media Mentions

Signals from CVEs in this product scope (125 CVEs).

Top CNAs Publishing CVEs For Communications Cloud Native Core Policy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
23.1.015.31.3%00
22.4.015.31.3%00
22.3.014.40.2%00
22.2.0276.21.7%00
22.1.336.934.4%11
22.1.029.899.8%22
1.9.027.416.8%00
1.5.037.032.6%00
1.15.0226.725.5%23
1.14.0657.513.0%17
1.11.036.611.3%01