Enterprise Manager Base Platform
Vendor:
First CVE: Apr 8, 2016 · Active for 10 years
155
Total CVEs
More Total CVEs than 99% of tracked products
17.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Enterprise Manager Base Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2016
10 years ago
Most Recent CVE
Jul 21, 2026
5 days ago
CVE Severity & Scoring
Enterprise Manager Base Platform155 CVEs
43%
40%
17%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (5.8%)
Network144 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (1.3%)
Attack Complexity
Low135 (87.1%)
High20 (12.9%)
Unknown0 (0.0%)
User Interaction
None126 (81.3%)
Unknown0 (0.0%)
Required29 (18.7%)
Privileges Required
Low29 (18.7%)
High42 (27.1%)
None84 (54.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (155 CVEs).
155 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11776HIGH Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention | Aug 22, 2018 | 8.1 | 99 | YES | YES |
CVE-2017-5645CRITICAL In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa | Apr 17, 2017 | 9.8 | 86 | NO | YES |
CVE-2019-0227HIGH A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec | May 1, 2019 | 7.5 | 84 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2020-5398HIGH In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R | Jan 17, 2020 | 7.5 | 73 | NO | NO |
CVE-2021-4104HIGH JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName | Dec 14, 2021 | 7.5 | 70 | NO | NO |
CVE-2022-23305CRITICAL By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv | Jan 18, 2022 | 9.8 | 68 | NO | NO |
CVE-2022-23302HIGH JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere | Jan 18, 2022 | 8.8 | 63 | NO | NO |
CVE-2021-34798HIGH Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 7.5 | 61 | NO | NO |
CVE-2021-36160HIGH A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 ( | Sep 16, 2021 | 7.5 | 59 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (155 CVEs).
CISA KEV
1 CVE
0.6% of CVEs· 96th percentile
Metasploit
1 CVE
0.6% of CVEs· 96th percentile
Nuclei
4 CVEs
2.6% of CVEs· 96th percentile
ExploitDB
3 CVEs
1.9% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (155 CVEs).
Media Mentions
Signals from CVEs in this product scope (155 CVEs).
Top CNAs Publishing CVEs For Enterprise Manager Base Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 24.1.0.0.0 | 35 | 7.8 | 0.3% | 0 | 0 |
| 13.5.0.0 | 58 | 7.8 | 9.4% | 0 | 0 |
| 13.4.0.0 | 54 | 8.0 | 16.6% | 1 | 3 |
| 13.3.0.0.0 | 10 | 6.4 | 7.0% | 0 | 1 |
| 13.3.0.0 | 58 | 7.0 | 6.6% | 1 | 4 |
| 13.3 | 4 | 6.2 | 4.2% | 0 | 0 |
| 13.2.1.0 | 6 | 7.2 | 19.7% | 0 | 0 |
| 13.2.0.0.0 | 10 | 6.4 | 7.0% | 0 | 1 |
| 13.2.0.0 | 36 | 6.3 | 3.8% | 0 | 1 |
| 13.2.0 | 2 | 7.6 | 2.1% | 0 | 0 |
| 13.2 | 4 | 6.2 | 4.2% | 0 | 0 |
| 13.1.0.0 | 1 | 4.3 | 2.0% | 0 | 0 |
| 13.1.0 | 2 | 7.6 | 2.1% | 0 | 0 |
| 12.1.0.5.0 | 8 | 6.5 | 7.6% | 0 | 1 |
| 12.1.0.5 | 40 | 6.1 | 5.9% | 0 | 2 |
| 12.1.0 | 2 | 7.6 | 2.1% | 0 | 0 |