Instantis Enterprisetrack

Vendor:

First CVE: Apr 17, 2017 · Active for 9 years

57
Total CVEs
More Total CVEs than 99% of tracked products
11.4
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
10.5%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Instantis Enterprisetrack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2017
9 years ago
Most Recent CVE
Dec 20, 2021
1,680 days ago

CVE Severity & Scoring

Instantis Enterprisetrack57 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local4 (7.0%)
Network52 (91.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low45 (78.9%)
High12 (21.1%)
Unknown0 (0.0%)
User Interaction
None51 (89.5%)
Unknown0 (0.0%)
Required6 (10.5%)
Privileges Required
Low6 (10.5%)
High1 (1.8%)
None50 (87.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori
Oct 7, 20219.899YESYES
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con
Oct 5, 20219.899YESYES
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by
Apr 8, 20197.893YESYES
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo
Dec 20, 20219.888NOYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.584NOYES
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Aug 7, 20209.883NOYES

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
6 CVEs
10.5% of CVEs· 98th percentile
Metasploit
4 CVEs
7.0% of CVEs· 97th percentile
Nuclei
10 CVEs
17.5% of CVEs· 98th percentile
ExploitDB
8 CVEs
14.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Instantis Enterprisetrack

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
17.3447.450.0%49
17.2457.451.2%510
17.1457.451.2%510