Communications Evolved Communications Application Server
Vendor:
First CVE: Aug 20, 2019 · Active for 6 years
39
Total CVEs
More Total CVEs than 97% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Communications Evolved Communications Application Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2019
6 years ago
Most Recent CVE
Dec 18, 2021
1,679 days ago
CVE Severity & Scoring
Communications Evolved Communications Application Server39 CVEs
77%
18%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.6%)
Network38 (97.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (43.6%)
High22 (56.4%)
Unknown0 (0.0%)
User Interaction
None32 (82.1%)
Unknown0 (0.0%)
Required7 (17.9%)
Privileges Required
Low1 (2.6%)
High0 (0.0%)
None38 (97.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2020-9547CRITICAL FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransacti | Mar 2, 2020 | 9.8 | 52 | NO | YES |
CVE-2020-9548CRITICAL FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-co | Mar 2, 2020 | 9.8 | 51 | NO | YES |
CVE-2019-10086HIGH In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property | Aug 20, 2019 | 7.3 | 39 | NO | NO |
CVE-2020-36179HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte | Jan 7, 2021 | 8.1 | 36 | NO | NO |
CVE-2019-20330CRITICAL FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. | Jan 3, 2020 | 9.8 | 36 | NO | NO |
CVE-2019-17531CRITICAL A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an ext | Oct 12, 2019 | 9.8 | 34 | NO | NO |
CVE-2019-16943CRITICAL A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an ext | Oct 1, 2019 | 9.8 | 34 | NO | NO |
CVE-2020-25649HIGH A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi | Dec 3, 2020 | 7.5 | 33 | NO | NO |
CVE-2019-16942CRITICAL A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an ext | Oct 1, 2019 | 9.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (39 CVEs).
Media Mentions
Signals from CVEs in this product scope (39 CVEs).
Top CNAs Publishing CVEs For Communications Evolved Communications Application Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.1 | 39 | 8.4 | 10.3% | 0 | 2 |