Communications Instant Messaging Server

Vendor:

First CVE: Apr 6, 2017 · Active for 9 years

57
Total CVEs
More Total CVEs than 99% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
5.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Communications Instant Messaging Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2017
9 years ago
Most Recent CVE
Jan 18, 2022
1,652 days ago

CVE Severity & Scoring

Communications Instant Messaging Server57 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local2 (3.5%)
Network55 (96.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (57.9%)
High24 (42.1%)
Unknown0 (0.0%)
User Interaction
None48 (84.2%)
Unknown0 (0.0%)
Required9 (15.8%)
Privileges Required
Low4 (7.0%)
High0 (0.0%)
None53 (93.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener
Apr 6, 20179.897YESYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv
Jan 18, 20229.868NONO
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f
May 20, 20207.066NOYES
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere
Jan 18, 20228.863NONO
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the pos
Jul 12, 20215.361NONO
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a su
Jul 14, 20207.560NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
3 CVEs
5.3% of CVEs· 98th percentile
Metasploit
2 CVEs
3.5% of CVEs· 97th percentile
Nuclei
8 CVEs
14.0% of CVEs· 97th percentile
ExploitDB
2 CVEs
3.5% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Communications Instant Messaging Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.127.04.2%00
10.0.1.5.0267.922.9%01
10.0.1.4.0198.414.4%14
10.0.1.3.049.230.2%01
10.0.1.2.039.817.3%00
10.0.149.462.1%22