« Back to list

Cisco

Cisco Business Process Automation: vulnerabilities and CVEs

Cisco Business Process Automation has 4 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 2 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical1
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-44487High (7.5)100%⚠ Active exploitationOct 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2021-44228Critical (10)100%⚠ Active exploitationDec 10, 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-44487High (7.5)100%⚠ Active exploitationOct 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2021-44228Critical (10)100%⚠ Active exploitationDec 10, 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…
CVE-2021-1576High (8.8)1.1%—Jul 8, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are…
CVE-2021-1574High (8.8)1.7%—Jul 8, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application2
  2. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Cisco