Flexcube Private Banking

Vendor:

First CVE: Sep 30, 2013 · Active for 12 years

75
Total CVEs
More Total CVEs than 99% of tracked products
9.4
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Flexcube Private Banking over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2013
12 years ago
Most Recent CVE
Feb 1, 2022
1,638 days ago

CVE Severity & Scoring

Flexcube Private Banking75 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local7 (9.3%)
Network66 (88.0%)
Unknown1 (1.3%)
Physical0 (0.0%)
Adjacent Network1 (1.3%)
Attack Complexity
Low59 (78.7%)
High15 (20.0%)
Unknown1 (1.3%)
User Interaction
None56 (74.7%)
Unknown1 (1.3%)
Required18 (24.0%)
Privileges Required
Low28 (37.3%)
High1 (1.3%)
None45 (60.0%)
Unknown1 (1.3%)

Top CVEs

Signals from CVEs in this product scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.584NOYES
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses
Dec 28, 20216.677NONO
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authenticatio
Sep 10, 20209.851NONO
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property
Aug 20, 20197.340NONO
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Jul 26, 20199.840NONO
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token se
Nov 6, 20199.837NONO
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.
Oct 16, 20199.836NONO
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a
Aug 30, 20197.533NONO
Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.
May 14, 20207.532NONO

Exploit Exposure

Signals from CVEs in this product scope (75 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.3% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (75 CVEs).

Media Mentions

Signals from CVEs in this product scope (75 CVEs).

Top CNAs Publishing CVEs For Flexcube Private Banking

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0110.08.3%00
2.2.0.196.83.3%00
2.2.0195.51.3%00
2.0.1255.81.7%00
2.0.0.037.14.5%00
2.0.0165.51.4%00
2.0110.08.3%00
1.7110.08.3%00
12.1.0.037.14.5%00
12.1.0467.013.7%01
12.0.3.037.14.5%00
12.0.325.85.3%00
12.0.227.14.7%00
12.0.1.037.14.5%00
12.0.1275.81.9%00
12.0.0427.012.1%01