Financial Services Behavior Detection Platform

Vendor:

First CVE: Apr 17, 2017 · Active for 9 years

12
Total CVEs
More Total CVEs than 91% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
16.7%
KEV Rate
Higher KEV Rate than 99% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Financial Services Behavior Detection Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2017
9 years ago
Most Recent CVE
Jan 21, 2025
553 days ago

CVE Severity & Scoring

Financial Services Behavior Detection Platform12 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High2 (16.7%)
Unknown0 (0.0%)
User Interaction
None7 (58.3%)
Unknown0 (0.0%)
Required5 (41.7%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None10 (83.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r
Apr 1, 20229.899YESYES
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run
Apr 1, 20229.898YESYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Mar 11, 20227.528NONO
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulne
Jul 21, 20218.328NONO
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows ab
Mar 16, 20227.526NONO
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an
Jan 24, 20226.525NONO
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more lik
Sep 22, 20215.925NONO
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments an
Nov 8, 20196.123NONO
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEd
Mar 16, 20225.421NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
2 CVEs
16.7% of CVEs· 99th percentile
Metasploit
2 CVEs
16.7% of CVEs· 98th percentile
Nuclei
3 CVEs
25.0% of CVEs· 98th percentile
ExploitDB
1 CVE
8.3% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Financial Services Behavior Detection Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.1.2.816.10.2%00
8.1.2.716.10.2%00
8.1.2.048.052.6%22
8.1.1.148.052.6%22
8.1.1.048.052.6%22
8.0.8.125.20.3%00
8.0.8.026.51.8%00
8.0.837.33.2%00
8.0.7.0.017.54.9%00
8.0.7.026.51.8%00
8.0.727.22.3%00
8.0.1127.22.3%00
6.1.119.889.0%01