Workload Manager

Vendor:

First CVE: Oct 4, 2017 · Active for 8 years

10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
20.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Workload Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2017
8 years ago
Most Recent CVE
Dec 3, 2020
2,059 days ago

CVE Severity & Scoring

Workload Manager10 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (20.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (50.0%)
High5 (50.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f
May 20, 20207.066NOYES
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a su
Jul 14, 20207.560NONO
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several second
Jun 26, 20207.531NONO
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the
Dec 3, 20207.530NONO
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process
Dec 23, 20197.024NONO
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Enc
Feb 24, 20204.823NONO
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers
Feb 24, 20204.822NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
2 CVEs
20.0% of CVEs· 98th percentile
Metasploit
2 CVEs
20.0% of CVEs· 97th percentile
Nuclei
4 CVEs
40.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
20.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Workload Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
19c97.042.0%13
18c97.042.0%13
12.2.0.197.150.4%24