Communications Messaging Server
Vendor:
First CVE: Jan 22, 2015 · Active for 11 years
41
Total CVEs
More Total CVEs than 98% of tracked products
5.9
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Communications Messaging Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2015
11 years ago
Most Recent CVE
Jan 18, 2022
1,651 days ago
CVE Severity & Scoring
Communications Messaging Server41 CVEs
37%
54%
10%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (24.4%)
Network29 (70.7%)
Unknown2 (4.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (78.0%)
High7 (17.1%)
Unknown2 (4.9%)
User Interaction
None29 (70.7%)
Unknown2 (4.9%)
Required10 (24.4%)
Privileges Required
Low5 (12.2%)
High0 (0.0%)
None34 (82.9%)
Unknown2 (4.9%)
Top CVEs
Signals from CVEs in this product scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5645CRITICAL In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa | Apr 17, 2017 | 9.8 | 86 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2021-4104HIGH JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName | Dec 14, 2021 | 7.5 | 70 | NO | NO |
CVE-2022-23305CRITICAL By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv | Jan 18, 2022 | 9.8 | 68 | NO | NO |
CVE-2022-23302HIGH JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere | Jan 18, 2022 | 8.8 | 63 | NO | NO |
CVE-2022-23307HIGH CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exi | Jan 18, 2022 | 8.8 | 57 | NO | NO |
CVE-2020-13954MEDIUM By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting ( | Nov 12, 2020 | 6.1 | 38 | NO | NO |
CVE-2019-0228CRITICAL Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. | Apr 17, 2019 | 9.8 | 35 | NO | NO |
CVE-2021-33813HIGH An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | Jun 16, 2021 | 7.5 | 34 | NO | NO |
CVE-2020-25649HIGH A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi | Dec 3, 2020 | 7.5 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (41 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.4% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (41 CVEs).
Media Mentions
Signals from CVEs in this product scope (41 CVEs).
Top CNAs Publishing CVEs For Communications Messaging Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1 | 37 | 7.2 | 16.0% | 0 | 0 |
| 8.0.2 | 6 | 6.8 | 13.1% | 0 | 0 |
| 8.0 | 3 | 6.8 | 2.3% | 0 | 0 |
| 7.0.5 | 2 | 7.5 | 2.2% | 0 | 0 |
| 7.0 | 1 | 5.3 | 2.3% | 0 | 0 |
| 6.3 | 1 | 5.3 | 2.3% | 0 | 0 |