Enterprise Manager Base Platform

Vendor:

First CVE: Apr 8, 2016 · Active for 10 years

155
Total CVEs
More Total CVEs than 99% of tracked products
17.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Enterprise Manager Base Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2016
10 years ago
Most Recent CVE
Jul 21, 2026
5 days ago

CVE Severity & Scoring

Enterprise Manager Base Platform155 CVEs
All CVEs352,713 CVEs
LowMediumHighCritical
Attack Vector
Local9 (5.8%)
Network144 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (1.3%)
Attack Complexity
Low135 (87.1%)
High20 (12.9%)
Unknown0 (0.0%)
User Interaction
None126 (81.3%)
Unknown0 (0.0%)
Required29 (18.7%)
Privileges Required
Low29 (18.7%)
High42 (27.1%)
None84 (54.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (155 CVEs).

155 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention
Aug 22, 20188.199YESYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.584NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName
Dec 14, 20217.570NONO
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv
Jan 18, 20229.868NONO
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere
Jan 18, 20228.863NONO
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20217.561NONO
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (
Sep 16, 20217.559NONO

Exploit Exposure

Signals from CVEs in this product scope (155 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· 96th percentile
Metasploit
1 CVE
0.6% of CVEs· 96th percentile
Nuclei
4 CVEs
2.6% of CVEs· 96th percentile
ExploitDB
3 CVEs
1.9% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (155 CVEs).

Media Mentions

Signals from CVEs in this product scope (155 CVEs).

Top CNAs Publishing CVEs For Enterprise Manager Base Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
24.1.0.0.0357.80.3%00
13.5.0.0587.89.4%00
13.4.0.0548.016.6%13
13.3.0.0.0106.47.0%01
13.3.0.0587.06.6%14
13.346.24.2%00
13.2.1.067.219.7%00
13.2.0.0.0106.47.0%01
13.2.0.0366.33.8%01
13.2.027.62.1%00
13.246.24.2%00
13.1.0.014.32.0%00
13.1.027.62.1%00
12.1.0.5.086.57.6%01
12.1.0.5406.15.9%02
12.1.027.62.1%00