Communications Session Report Manager
Vendor:
First CVE: Aug 2, 2018 · Active for 7 years
69
Total CVEs
More Total CVEs than 99% of tracked products
13.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Communications Session Report Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2018
7 years ago
Most Recent CVE
Jan 24, 2022
1,645 days ago
CVE Severity & Scoring
Communications Session Report Manager69 CVEs
26%
62%
9%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (7.2%)
Network61 (88.4%)
Unknown0 (0.0%)
Physical1 (1.4%)
Adjacent Network2 (2.9%)
Attack Complexity
Low43 (62.3%)
High26 (37.7%)
Unknown0 (0.0%)
User Interaction
None49 (71.0%)
Unknown0 (0.0%)
Required20 (29.0%)
Privileges Required
Low5 (7.2%)
High2 (2.9%)
None62 (89.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (69 CVEs).
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11023MEDIUM In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's | Apr 29, 2020 | 6.1 | 95 | YES | YES |
CVE-2019-0211HIGH In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by | Apr 8, 2019 | 7.8 | 93 | YES | YES |
CVE-2021-44790CRITICAL A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo | Dec 20, 2021 | 9.8 | 88 | NO | YES |
CVE-2019-0227HIGH A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec | May 1, 2019 | 7.5 | 84 | NO | YES |
CVE-2020-11984CRITICAL Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | Aug 7, 2020 | 9.8 | 83 | NO | YES |
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2020-5398HIGH In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R | Jan 17, 2020 | 7.5 | 73 | NO | NO |
CVE-2021-44224HIGH A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de | Dec 20, 2021 | 8.2 | 72 | NO | NO |
CVE-2020-9490HIGH Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to | Aug 7, 2020 | 7.5 | 68 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (69 CVEs).
CISA KEV
2 CVEs
2.9% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.3% of CVEs· 97th percentile
ExploitDB
5 CVEs
7.2% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (69 CVEs).
Media Mentions
Signals from CVEs in this product scope (69 CVEs).
Top CNAs Publishing CVEs For Communications Session Report Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.2.1 | 9 | 6.4 | 49.3% | 1 | 2 |
| 8.2.0 | 15 | 6.3 | 42.0% | 2 | 4 |
| 8.1.1 | 15 | 6.3 | 42.0% | 2 | 4 |
| 8.1.0 | 7 | 6.2 | 27.9% | 1 | 2 |
| 8.0.0 | 7 | 6.2 | 27.9% | 1 | 2 |