Transportation Management

Vendor:

First CVE: Dec 6, 2015 · Active for 10 years

27
Total CVEs
More Total CVEs than 96% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 21% of tracked products
11.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Transportation Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2015
10 years ago
Most Recent CVE
Oct 18, 2022
1,379 days ago

CVE Severity & Scoring

Transportation Management27 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local1 (3.7%)
Network26 (96.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (77.8%)
High6 (22.2%)
Unknown0 (0.0%)
User Interaction
None20 (74.1%)
Unknown0 (0.0%)
Required7 (25.9%)
Privileges Required
Low13 (48.1%)
High3 (11.1%)
None11 (40.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener
Apr 6, 20179.897YESYES
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f
May 20, 20207.066NOYES
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused
Dec 6, 20155.339NONO
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). The supported version that is affected is 6.4.3. Easily exploit
Oct 20, 20215.433NONO
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixati
Dec 23, 20197.530NONO
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Enc
Feb 24, 20204.823NONO
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers
Feb 24, 20204.822NONO

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
3 CVEs
11.1% of CVEs· 98th percentile
Metasploit
2 CVEs
7.4% of CVEs· 97th percentile
Nuclei
4 CVEs
14.8% of CVEs· 98th percentile
ExploitDB
3 CVEs
11.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Transportation Management

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.5.154.90.6%00
6.4.3135.32.9%00
6.4.265.61.1%00
6.4.175.11.3%00
6.4.034.41.3%00
6.3.7.115.41.2%00
6.3.7146.125.6%34
6.3.6.115.41.2%00
6.3.665.728.0%22
6.3.5.115.41.2%00
6.3.565.728.0%22
6.3.4.115.41.2%00
6.3.465.728.0%22
6.3.365.728.0%22
6.3.265.728.0%22
6.3.165.728.0%22
6.3.035.523.6%11
6.2.1124.80.7%00
6.225.720.2%00
6.115.338.7%00