Managed File Transfer
Vendor:
First CVE: Feb 23, 2018 · Active for 8 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Managed File Transfer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2018
8 years ago
Most Recent CVE
Jan 27, 2022
1,639 days ago
CVE Severity & Scoring
Managed File Transfer15 CVEs
27%
67%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (20.0%)
Network12 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (73.3%)
High4 (26.7%)
Unknown0 (0.0%)
User Interaction
None14 (93.3%)
Unknown0 (0.0%)
Required1 (6.7%)
Privileges Required
Low5 (33.3%)
High0 (0.0%)
None10 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13935HIGH The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl | Jul 14, 2020 | 7.5 | 77 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2020-9484HIGH When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f | May 20, 2020 | 7.0 | 66 | NO | YES |
CVE-2021-33037MEDIUM Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the pos | Jul 12, 2021 | 5.3 | 61 | NO | NO |
CVE-2020-13934HIGH An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a su | Jul 14, 2020 | 7.5 | 60 | NO | NO |
CVE-2021-25122HIGH When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amo | Mar 1, 2021 | 7.5 | 33 | NO | NO |
CVE-2018-1000613CRITICAL Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Cl | Jul 9, 2018 | 9.8 | 32 | NO | NO |
CVE-2019-17359HIGH The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is f | Oct 8, 2019 | 7.5 | 29 | NO | NO |
CVE-2018-1305MEDIUM Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servle | Feb 23, 2018 | 6.5 | 28 | NO | NO |
CVE-2021-25329HIGH The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that | Mar 1, 2021 | 7.0 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
13.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Managed File Transfer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 19.1.0.0.0 | 1 | 7.1 | 1.1% | 0 | 0 |
| 12.2.1.4.0 | 11 | 6.9 | 39.5% | 0 | 2 |
| 12.2.1.3.0 | 15 | 7.1 | 30.6% | 0 | 2 |
| 12.1.3.0.0 | 3 | 7.9 | 7.7% | 0 | 0 |