Real Time Decision Server
Vendor:
First CVE: Aug 2, 2018 · Active for 7 years
7
Total CVEs
More Total CVEs than 85% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Real Time Decision Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2018
7 years ago
Most Recent CVE
Jul 14, 2021
1,840 days ago
CVE Severity & Scoring
Real Time Decision Server7 CVEs
71%
29%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (42.9%)
Network3 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (14.3%)
Attack Complexity
Low5 (71.4%)
High2 (28.6%)
Unknown0 (0.0%)
User Interaction
None3 (42.9%)
Unknown0 (0.0%)
Required4 (57.1%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0227HIGH A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec | May 1, 2019 | 7.5 | 84 | NO | YES |
CVE-2018-8032MEDIUM Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | Aug 2, 2018 | 6.1 | 26 | NO | NO |
CVE-2020-11979HIGH As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the | Oct 1, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-10219MEDIUM A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments an | Nov 8, 2019 | 6.1 | 23 | NO | NO |
CVE-2021-36374MEDIUM When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even f | Jul 14, 2021 | 5.5 | 21 | NO | NO |
CVE-2021-36373MEDIUM When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs | Jul 14, 2021 | 5.5 | 21 | NO | NO |
CVE-2020-1945MEDIUM Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensiti | May 14, 2020 | 6.3 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Real Time Decision Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.1.0 | 3 | 6.6 | 34.8% | 0 | 1 |
| 3.2.0.0 | 4 | 6.2 | 3.9% | 0 | 0 |
| 11.1.1.9.0 | 3 | 6.2 | 4.5% | 0 | 0 |