3scale Api Management
Vendor:
First CVE: Nov 27, 2019 · Active for 6 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact 3scale Api Management over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 27, 2019
6 years ago
Most Recent CVE
Oct 24, 2024
639 days ago
CVE Severity & Scoring
3scale Api Management12 CVEs
33%
67%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (41.7%)
Network7 (58.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low8 (66.7%)
High0 (0.0%)
None4 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1414HIGH 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access | Oct 19, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-3656HIGH A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest t | Mar 4, 2022 | 8.8 | 28 | NO | NO |
CVE-2019-10216HIGH In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abu | Nov 27, 2019 | 7.8 | 26 | NO | NO |
CVE-2021-3609HIGH .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escala | Mar 3, 2022 | 7.0 | 24 | NO | NO |
CVE-2021-3412HIGH It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information | Jun 1, 2021 | 7.3 | 24 | NO | NO |
CVE-2019-14852HIGH A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access | Mar 18, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-20252MEDIUM A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges in certain queries allowing a ma | Feb 23, 2021 | 6.5 | 22 | NO | NO |
CVE-2024-10295HIGH A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication hea | Oct 24, 2024 | 7.5 | 21 | NO | NO |
CVE-2020-14388MEDIUM A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated use | Jun 2, 2021 | 6.3 | 21 | NO | NO |
CVE-2022-0330HIGH A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user | Mar 25, 2022 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For 3scale Api Management
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.6 | 1 | 7.8 | 2.3% | 0 | 0 |
| 2.0 | 11 | 7.1 | 0.6% | 0 | 0 |