Retail Eftlink

Vendor:

First CVE: Oct 4, 2017 · Active for 8 years

10
Total CVEs
More Total CVEs than 89% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Retail Eftlink over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2017
8 years ago
Most Recent CVE
Dec 18, 2021
1,683 days ago

CVE Severity & Scoring

Retail Eftlink10 CVEs
All CVEs353,240 CVEs
LowMediumHigh
Attack Vector
Local2 (20.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (60.0%)
High4 (40.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp
Jul 15, 20215.391NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the
Oct 1, 20207.525NONO
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced t
Oct 14, 20217.523NONO
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments an
Nov 8, 20196.123NONO
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even f
Jul 14, 20215.521NONO
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs
Jul 14, 20215.521NONO
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests fro
Nov 28, 20204.820NONO
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which coul
Apr 27, 20203.720NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
1 CVE
10.0% of CVEs· 98th percentile
Metasploit
2 CVEs
20.0% of CVEs· 98th percentile
Nuclei
2 CVEs
20.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
20.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Retail Eftlink

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
21.0.026.755.5%00
20.0.155.741.3%01
20.0.026.28.2%00
19.0.165.720.6%00
18.0.135.236.8%00
17.0.235.236.8%00
16.0.335.236.8%00
16.0.218.1100.0%11
15.0.213.78.1%00
15.0.118.1100.0%11
1.1.12418.1100.0%11