Communications Instant Messaging Server
Vendor:
First CVE: Apr 6, 2017 · Active for 9 years
57
Total CVEs
More Total CVEs than 99% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
5.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Communications Instant Messaging Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2017
9 years ago
Most Recent CVE
Jan 18, 2022
1,652 days ago
CVE Severity & Scoring
Communications Instant Messaging Server57 CVEs
9%
67%
25%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (3.5%)
Network55 (96.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (57.9%)
High24 (42.1%)
Unknown0 (0.0%)
User Interaction
None48 (84.2%)
Unknown0 (0.0%)
Required9 (15.8%)
Privileges Required
Low4 (7.0%)
High0 (0.0%)
None53 (93.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2017-12617HIGH When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation | Oct 4, 2017 | 8.1 | 99 | YES | YES |
CVE-2016-8735CRITICAL Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener | Apr 6, 2017 | 9.8 | 97 | YES | YES |
CVE-2017-5645CRITICAL In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa | Apr 17, 2017 | 9.8 | 86 | NO | YES |
CVE-2020-13935HIGH The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl | Jul 14, 2020 | 7.5 | 77 | NO | YES |
CVE-2022-23305CRITICAL By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv | Jan 18, 2022 | 9.8 | 68 | NO | NO |
CVE-2020-9484HIGH When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f | May 20, 2020 | 7.0 | 66 | NO | YES |
CVE-2022-23302HIGH JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere | Jan 18, 2022 | 8.8 | 63 | NO | NO |
CVE-2021-33037MEDIUM Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the pos | Jul 12, 2021 | 5.3 | 61 | NO | NO |
CVE-2020-13934HIGH An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a su | Jul 14, 2020 | 7.5 | 60 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (57 CVEs).
CISA KEV
3 CVEs
5.3% of CVEs· 98th percentile
Metasploit
2 CVEs
3.5% of CVEs· 97th percentile
Nuclei
8 CVEs
14.0% of CVEs· 97th percentile
ExploitDB
2 CVEs
3.5% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (57 CVEs).
Media Mentions
Signals from CVEs in this product scope (57 CVEs).
Top CNAs Publishing CVEs For Communications Instant Messaging Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1 | 2 | 7.0 | 4.2% | 0 | 0 |
| 10.0.1.5.0 | 26 | 7.9 | 22.9% | 0 | 1 |
| 10.0.1.4.0 | 19 | 8.4 | 14.4% | 1 | 4 |
| 10.0.1.3.0 | 4 | 9.2 | 30.2% | 0 | 1 |
| 10.0.1.2.0 | 3 | 9.8 | 17.3% | 0 | 0 |
| 10.0.1 | 4 | 9.4 | 62.1% | 2 | 2 |