Retail Bulk Data Integration

Vendor:

First CVE: Jul 18, 2018 · Active for 8 years

12
Total CVEs
More Total CVEs than 91% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
8.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Retail Bulk Data Integration over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 18, 2018
8 years ago
Most Recent CVE
Apr 1, 2022
1,579 days ago

CVE Severity & Scoring

Retail Bulk Data Integration12 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local4 (33.3%)
Network8 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High4 (33.3%)
Unknown0 (0.0%)
User Interaction
None5 (41.7%)
Unknown0 (0.0%)
Required7 (58.3%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None9 (75.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run
Apr 1, 20229.898YESYES
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when crea
Sep 19, 20217.528NONO
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 m
Sep 19, 20206.527NONO
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an
Jan 24, 20226.525NONO
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS bec
Oct 2, 20196.122NONO
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even f
Jul 14, 20215.521NONO
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs
Jul 14, 20215.521NONO
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensiti
May 14, 20206.321NONO
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now supersede
Dec 7, 20205.520NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
1 CVE
8.3% of CVEs· 98th percentile
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
8.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Retail Bulk Data Integration

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
19.0.135.82.3%00
16.0.3.095.913.6%00
16.0.328.753.5%11
16.026.21.4%00
15.0.3.024.64.6%00
15.016.31.8%00