Enterprise Manager For Virtualization
Vendor:
First CVE: Dec 1, 2017 · Active for 8 years
8
Total CVEs
More Total CVEs than 87% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Enterprise Manager For Virtualization over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2017
8 years ago
Most Recent CVE
Aug 20, 2019
2,533 days ago
CVE Severity & Scoring
Enterprise Manager For Virtualization8 CVEs
13%
13%
75%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7525CRITICAL A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by se | Feb 6, 2018 | 9.8 | 50 | NO | NO |
CVE-2019-10086HIGH In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property | Aug 20, 2019 | 7.3 | 40 | NO | NO |
CVE-2018-14721CRITICAL FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class | Jan 2, 2019 | 10.0 | 36 | NO | NO |
CVE-2018-14718CRITICAL FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserializati | Jan 2, 2019 | 9.8 | 36 | NO | NO |
CVE-2018-14720CRITICAL FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorph | Jan 2, 2019 | 9.8 | 34 | NO | NO |
CVE-2018-14719CRITICAL FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from po | Jan 2, 2019 | 9.8 | 34 | NO | NO |
CVE-2017-15095CRITICAL A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending th | Feb 6, 2018 | 9.8 | 32 | NO | NO |
CVE-2017-15707MEDIUM In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially craf | Dec 1, 2017 | 6.2 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Enterprise Manager For Virtualization
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 13.4.0.0 | 1 | 7.3 | 29.8% | 0 | 0 |
| 13.3.1 | 6 | 9.8 | 14.4% | 0 | 0 |
| 13.2.3 | 7 | 9.3 | 13.0% | 0 | 0 |
| 13.2.2 | 7 | 9.3 | 13.0% | 0 | 0 |