Vulnerabilities used by  Prophetspider


This information is provided by Ransomware-Vulnerability-Matrix


This is the list of vulnerabilities that have been observed during intrusions by  
Prophetspider

Vendor Product CVE Source
Apache Log4j  🔴  CVE-2021-44228 ("Log4Shell") secureworks.com
Apache Log4j  🟠  CVE-2021-4104 secureworks.com
Apache Struts  🔴  CVE-2017-5638 secureworks.com
Citrix ShareFile Storage Zones Controller  🔴  CVE-2021-22941 crowdstrike.com
Java Applications Jboss Application Server  🔴  CVE-2017-7504 secureworks.com
Oracle WebLogic  🔴  CVE-2020-14882 secureworks.com
Oracle WebLogic  🔴  CVE-2020-14750 secureworks.com
Oracle E-Business  🌕  CVE-2016-0545 secureworks.com
Sitecore Sitecore XP  🔴  CVE-2021-42237 secureworks.com

CVE Severity Levels

Severity Score Range Description
⚪️ Low 0.1 - 3.9 Minor impact on the system; typically does not require immediate action.
🌕 Medium 4.0 - 6.9 Moderate impact; may require action but is generally not urgent.
🟠 High 7.0 - 8.9 Significant impact; needs attention soon to prevent potential exploitation.
🔴 Critical 9.0 - 10.0 Severe impact; requires immediate action due to the high risk of exploitation and potential for serious damage.