Transportation Management
Vendor:
First CVE: Dec 6, 2015 · Active for 10 years
27
Total CVEs
More Total CVEs than 96% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 21% of tracked products
11.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Transportation Management over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2015
10 years ago
Most Recent CVE
Oct 18, 2022
1,379 days ago
CVE Severity & Scoring
Transportation Management27 CVEs
70%
15%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.7%)
Network26 (96.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (77.8%)
High6 (22.2%)
Unknown0 (0.0%)
User Interaction
None20 (74.1%)
Unknown0 (0.0%)
Required7 (25.9%)
Privileges Required
Low13 (48.1%)
High3 (11.1%)
None11 (40.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2017-12617HIGH When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation | Oct 4, 2017 | 8.1 | 99 | YES | YES |
CVE-2016-8735CRITICAL Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener | Apr 6, 2017 | 9.8 | 97 | YES | YES |
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
CVE-2020-9484HIGH When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f | May 20, 2020 | 7.0 | 66 | NO | YES |
CVE-2015-3195MEDIUM The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused | Dec 6, 2015 | 5.3 | 39 | NO | NO |
CVE-2021-35616MEDIUM Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). The supported version that is affected is 6.4.3. Easily exploit | Oct 20, 2021 | 5.4 | 33 | NO | NO |
CVE-2019-17563HIGH When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixati | Dec 23, 2019 | 7.5 | 30 | NO | NO |
CVE-2019-17569MEDIUM The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Enc | Feb 24, 2020 | 4.8 | 23 | NO | NO |
CVE-2020-1935MEDIUM In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers | Feb 24, 2020 | 4.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
3 CVEs
11.1% of CVEs· 98th percentile
Metasploit
2 CVEs
7.4% of CVEs· 97th percentile
Nuclei
4 CVEs
14.8% of CVEs· 98th percentile
ExploitDB
3 CVEs
11.1% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Transportation Management
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.5.1 | 5 | 4.9 | 0.6% | 0 | 0 |
| 6.4.3 | 13 | 5.3 | 2.9% | 0 | 0 |
| 6.4.2 | 6 | 5.6 | 1.1% | 0 | 0 |
| 6.4.1 | 7 | 5.1 | 1.3% | 0 | 0 |
| 6.4.0 | 3 | 4.4 | 1.3% | 0 | 0 |
| 6.3.7.1 | 1 | 5.4 | 1.2% | 0 | 0 |
| 6.3.7 | 14 | 6.1 | 25.6% | 3 | 4 |
| 6.3.6.1 | 1 | 5.4 | 1.2% | 0 | 0 |
| 6.3.6 | 6 | 5.7 | 28.0% | 2 | 2 |
| 6.3.5.1 | 1 | 5.4 | 1.2% | 0 | 0 |
| 6.3.5 | 6 | 5.7 | 28.0% | 2 | 2 |
| 6.3.4.1 | 1 | 5.4 | 1.2% | 0 | 0 |
| 6.3.4 | 6 | 5.7 | 28.0% | 2 | 2 |
| 6.3.3 | 6 | 5.7 | 28.0% | 2 | 2 |
| 6.3.2 | 6 | 5.7 | 28.0% | 2 | 2 |
| 6.3.1 | 6 | 5.7 | 28.0% | 2 | 2 |
| 6.3.0 | 3 | 5.5 | 23.6% | 1 | 1 |
| 6.2.11 | 2 | 4.8 | 0.7% | 0 | 0 |
| 6.2 | 2 | 5.7 | 20.2% | 0 | 0 |
| 6.1 | 1 | 5.3 | 38.7% | 0 | 0 |