Tuxedo

Vendor:

First CVE: Feb 15, 2016 · Active for 10 years

16
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tuxedo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 15, 2016
10 years ago
Most Recent CVE
Jan 18, 2022
1,652 days ago

CVE Severity & Scoring

Tuxedo16 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (6.3%)
Network14 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.3%)
Attack Complexity
Low9 (56.3%)
High7 (43.8%)
Unknown0 (0.0%)
User Interaction
None15 (93.8%)
Unknown0 (0.0%)
Required1 (6.3%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None11 (68.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.584NOYES
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName
Dec 14, 20217.570NONO
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv
Jan 18, 20229.868NONO
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere
Jan 18, 20228.863NONO
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exi
Jan 18, 20228.857NONO
Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Easily ex
Nov 14, 201710.031NONO
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Nov 15, 20184.729NOYES
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the privat
Oct 30, 20185.926NONO
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Aug 2, 20186.126NONO
Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 12.1.1, 12.1.3 and 12.2.2. Easily exploitabl
Jul 18, 20188.624NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
12.5% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Tuxedo

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.2.2.0.048.765.5%00
12.2.268.11.6%00
12.1.387.714.0%01
12.1.1.0.056.024.6%02
12.1.1.015.910.7%00
12.1.168.11.6%00
11.1.157.91.4%00