# CVSS v2: Low Impact Score

CVEs whose CVSS v2 impact sub-score is 2.9 or lower.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/metrics-cvss-metric-v2-impact-score/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs whose CVSS v2 impact sub-score is 2.9 or lower.

Example 14 of 19 in **Filters › CVSS v2** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `metrics.cvss_metric_v2.impact_score` · `operator` `lte`

`metrics.cvss_metric_v2.impact_score` is the impact sub-score, in the CVSS v2 metric (`metrics.cvss_metric_v2`, one entry per scoring source).

`lte` matches `2.9` and below.

In the response, look at `results[].metrics.cvss_metric_v2[].impact_score`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `metrics.cvss_metric_v2.impact_score` |
| `filters.must[0].type` | body | `lte` |
| `filters.must[0].value` | body | `2.9` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "metrics.cvss_metric_v2.impact_score",
        "type": "lte",
        "value": 2.9
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown; results[].configurations: first 10 items; results[].enrichment.cpe: first 10 items; results[].enrichment.cwe[].capec_id: first 10 items; results[].configurations[].nodes[].cpe_match: first 10 items

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 81614,
  "results": [
    {
      "id": "CVE-2021-32671",
      "source_identifier": "user@github.com",
      "published": "2021-06-07T22:15:07Z",
      "last_modified": "2026-06-17T03:53:23Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made after v0.1.0-beta.16 (our last beta before v1.0.0) and was not noticed or documented. This allowed for any user to type malicious HTML markup within certain user input fields and have this execute on client browsers. The example which led to the discovery of this vulnerability was in the forum search box. Entering faux-malicious HTML markup, such as <script>alert('test')</script> resulted in an alert box appearing on the forum. This attack could also be modified to perform AJAX requests on behalf of a user, possibly deleting discussions, modifying their settings or profile, or even modifying settings on the Admin panel if the attack was targetted towards a privileged user. All Flarum communities that run flarum v1.0.0 or v1.0.1 are impacted. The vulnerability has been fixed and published as flarum/core v1.0.2. All communities running Flarum v1.0 have to upgrade as soon as possible to v1.0.2."
        },
        {
          "lang": "es",
          "value": "\"Flarum es un software de foros para construir comunidades. El sistema de traducción de Flarum permitía que las entradas de cadena se convirtieran en nodos HTML DOM cuando son renderizadas. Este cambio se realizó después de la versión v0.1.0-beta.16 (nuestra última beta versiones anteriores a v1.0.0) y no fue advertido ni documentado. Esto permitía que cualquier usuario escribiera marcas HTML maliciosas dentro de determinados campos de entrada del usuario y que éstas se ejecutaran en los navegadores de los clientes. El ejemplo que condujo al descubrimiento de esta vulnerabilidad fue en el cuadro de búsqueda del foro. La introducción de marcas HTML falsamente maliciosas, como (script)alert(\"\"test\"\")(/script) resultado a la aparición de un cuadro de alerta en el foro. Este ataque también podía ser modificado para llevar a cabo peticiones AJAX en nombre de un usuario, posiblemente borrando discusiones, modificando su configuración o perfil, o incluso modificando la configuración en el panel de administración si el ataque estaba dirigido a un usuario privilegiado. Todas las comunidades de Flarum que ejecutan flarum versiones v1.0.0 o v1.0.1 están afectadas. La vulnerabilidad ha sido corregida y publicada como flarum/core versión v1.0.2. Todas las comunidades que ejecutan Flarum versión v1.0, tienen que actualizar lo antes posible a la v1.0.2"
        }
      ],
      "references": [
        {
          "url": "https://github.com/flarum/core/commit/440bed81b8019dff00642c8f493b4909d505a28a",
          "source": "user@github.com",
          "tags": [
            "Patch",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/flarum/core/security/advisories/GHSA-5qjq-69w6-fg57",
          "source": "user@github.com",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://packagist.org/packages/flarum/core",
          "source": "user@github.com",
          "tags": [
            "Product",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/flarum/core/commit/440bed81b8019dff00642c8f493b4909d505a28a",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Patch",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/flarum/core/security/advisories/GHSA-5qjq-69w6-fg57",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://packagist.org/packages/flarum/core",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Product",
            "Third Party Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@github.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          },
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
              "access_vector": "NETWORK",
              "access_complexity": "MEDIUM",
              "authentication": "NONE",
              "confidentiality_impact": "NONE",
              "integrity_impact": "PARTIAL",
              "availability_impact": "NONE",
              "base_score": 4.3,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "MEDIUM",
            "exploitability_score": 8.6,
            "impact_score": 2.9,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": true
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@github.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-79"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:flarum:flarum:1.0.0:*:*:*:*:*:*:*",
                  "match_criteria_id": "3241FCD1-F5B7-4447-8FF9-6C02EEBB846D",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:flarum:flarum:1.0.1:*:*:*:*:*:*:*",
                  "match_criteria_id": "48C22B7B-9BD3-4AA4-9DB7-1CE3D837E5C2",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:flarum:flarum:1.0.0:*:*:*:*:*:*:*",
            "vendor": "flarum",
            "product": "flarum",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.0.0",
            "affected_versions_last": "1.0.0"
          },
          {
            "criteria": "cpe:2.3:a:flarum:flarum:1.0.1:*:*:*:*:*:*:*",
            "vendor": "flarum",
            "product": "flarum",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.0.1",
            "affected_versions_last": "1.0.1"
          }
        ],
        "cwe": [
          {
            "id": 79,
            "owasptop10_2021": "A03 Injection",
            "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
            "description": "The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.",
            "capec_id": [
              63,
              85,
              209,
              588,
              591,
              592
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis",
              "Black Box"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.39738,
          "percentile": 0.98558,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2019-16649",
      "source_identifier": "user@mitre.org",
      "published": "2019-09-21T02:15:11Z",
      "last_modified": "2026-06-17T02:22:29Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC."
        },
        {
          "lang": "es",
          "value": "En los productos Supermicro H11, H12, M11, X9, X10 y X11, una combinación de problemas de cifrado y autenticación en el servicio multimedia virtual permite la captura de credenciales de BMC y datos transferidos mediante dispositivos multimedia virtuales. Los atacantes pueden usar credenciales capturadas para conectar dispositivos USB virtuales en el servidor administrado por el BMC."
        }
      ],
      "references": [
        {
          "url": "https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/",
          "source": "user@mitre.org",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/eclypsium/USBAnywhere",
          "source": "user@mitre.org",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://www.supermicro.com/support/security_BMC_virtual_media.cfm",
          "source": "user@mitre.org",
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/eclypsium/USBAnywhere",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://www.supermicro.com/support/security_BMC_virtual_media.cfm",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
              "access_vector": "NETWORK",
              "access_complexity": "LOW",
              "authentication": "NONE",
              "confidentiality_impact": "PARTIAL",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 5.0,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "MEDIUM",
            "exploitability_score": 10.0,
            "impact_score": 2.9,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-287"
            },
            {
              "lang": "en",
              "value": "CWE-326"
            },
            {
              "lang": "en",
              "value": "CWE-522"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dai-n_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "CD238074-8099-4516-B4AA-C4D05F89B83D",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dai-n:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "0C5967E7-B9A7-4F23-B966-51F5C82B2529",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dac_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "3AB3D65D-AD05-4A01-B6C8-FDF81FDA4259",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dac:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "D3600406-96B2-4E52-B5F9-9ABCED307EEC",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dph-tq_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "0F1087F2-C3BD-43CE-AE9D-22B632DD6590",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dph-tq:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "03E3CB77-7874-4B9B-B6D9-69D42304D6BE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dph-i_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "0C93FDBA-87B0-4D5D-BB1F-1E04D53334CC",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dph-i:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "F149C888-F3AF-49D4-BBBF-99ABC8E8CEDE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dph-t_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "C94E1B64-406F-4E7F-99F5-3E414DB31A08",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dph-t:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "9780452F-4264-4069-9378-FE7F01D7ED1E",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dps-re_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "EE31D559-AC43-4A83-91EF-4CE5E2E5E121",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dps-re:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "ED8E7045-1721-4629-B92C-F35C0B074245",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dsf-e_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "F06BA5D3-990F-44B6-921D-B626BF8F7093",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dsf-e:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "BBDD9667-CE5C-487D-BC40-506D3722AD4C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dsn-ts_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "8848EAB8-5BA7-4BF7-8E30-6C5808CC1854",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dsn-ts:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "EA8F01F8-FA29-4E46-858F-149F94C8DBD4",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dsn-tsq_firmware:1.71.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "EAFAF0BF-B6C6-4EE2-8D66-11BCDEFFA5E7",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dsn-tsq:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "DECCF4B6-A0FD-419E-A61B-7BC023555E7A",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:supermicro:x11dsc+_firmware:1.74:*:*:*:*:*:*:*",
                  "match_criteria_id": "9C71B14D-14F2-49C9-ACF4-0A6B56E7FFF4",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:supermicro:x11dsc+:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "6442E1D1-53D8-49F4-8D51-08CE45850A77",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:o:supermicro:x11dai-n_firmware:1.71.5:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dai-n_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.71.5",
            "affected_versions_last": "1.71.5"
          },
          {
            "criteria": "cpe:2.3:h:supermicro:x11dai-n:-:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dai-n",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:supermicro:x11dac_firmware:1.71.5:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dac_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.71.5",
            "affected_versions_last": "1.71.5"
          },
          {
            "criteria": "cpe:2.3:h:supermicro:x11dac:-:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dac",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:supermicro:x11dph-tq_firmware:1.71.5:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dph-tq_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.71.5",
            "affected_versions_last": "1.71.5"
          },
          {
            "criteria": "cpe:2.3:h:supermicro:x11dph-tq:-:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dph-tq",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:supermicro:x11dph-i_firmware:1.71.5:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dph-i_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.71.5",
            "affected_versions_last": "1.71.5"
          },
          {
            "criteria": "cpe:2.3:h:supermicro:x11dph-i:-:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dph-i",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:supermicro:x11dph-t_firmware:1.71.5:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dph-t_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.71.5",
            "affected_versions_last": "1.71.5"
          },
          {
            "criteria": "cpe:2.3:h:supermicro:x11dph-t:-:*:*:*:*:*:*:*",
            "vendor": "supermicro",
            "product": "x11dph-t",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": [
          {
            "id": 522,
            "owasptop10_2021": "A04 Insecure Design",
            "name": "Insufficiently Protected Credentials",
            "description": "The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.",
            "capec_id": [
              50,
              102,
              474,
              509,
              551,
              555,
              560,
              561,
              600,
              644
            ],
            "scope": [
              "Access Control"
            ],
            "impact": [
              "Gain Privileges or Assume Identity"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          },
          {
            "id": 326,
            "owasptop10_2021": "A02 Cryptographic Failures",
            "name": "Inadequate Encryption Strength",
            "description": "The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.",
            "capec_id": [
              20,
              112,
              192
            ],
            "scope": [
              "Access Control",
              "Confidentiality"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          },
          {
            "id": 287,
            "owasptop10_2021": "A07 Identification and Authentication Failures",
            "name": "Improper Authentication",
            "description": "When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.",
            "capec_id": [
              22,
              57,
              94,
              114,
              115,
              151,
              194,
              593,
              633,
              650
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Read Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Static Analysis",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Static Analysis",
              "Manual Static Analysis - Binary or Bytecode",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.0092,
          "percentile": 0.58788,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2016-0898",
      "source_identifier": "user@emc.com",
      "published": "2018-03-29T22:29:00Z",
      "last_modified": "2026-06-17T00:38:26Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM."
        },
        {
          "lang": "es",
          "value": "Los tiles MySQL para PCF, en versiones 1.7.x anteriores a la 1.7.10, registran la clave de acceso AWS en texto plano. Estas credenciales se registraron en los registros del componente Service Backup en lugar de en el registro del sistema, por lo que no se expusieron fuera de la máquina virtual Service Backup."
        }
      ],
      "references": [
        {
          "url": "http://www.securityfocus.com/bid/95146",
          "source": "user@emc.com",
          "tags": [
            "Third Party Advisory",
            "VDB Entry"
          ]
        },
        {
          "url": "https://pivotal.io/security/cve-2016-0898",
          "source": "user@emc.com",
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "http://www.securityfocus.com/bid/95146",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Third Party Advisory",
            "VDB Entry"
          ]
        },
        {
          "url": "https://pivotal.io/security/cve-2016-0898",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
              "access_vector": "NETWORK",
              "access_complexity": "LOW",
              "authentication": "NONE",
              "confidentiality_impact": "PARTIAL",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 5.0,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "MEDIUM",
            "exploitability_score": 10.0,
            "impact_score": 2.9,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-255"
            },
            {
              "lang": "en",
              "value": "CWE-532"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "95444087-9535-4918-9413-DA9A16603938",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.1:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "83178D2C-2FD4-444F-BD6A-1F7736F73137",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.2:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "E439A8D1-D1C3-4867-8D94-58B71CD209A8",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.3:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "11819FC0-15E2-43D5-9B56-509BE9C7955E",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.4:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "575EFDE7-2296-4BEA-A9C3-A11F566ABB73",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.1:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "482E1D69-17DF-4FCB-9863-5079677343A3",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.2:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "EF99A4A6-F870-4BE6-B3ED-F9308ED3D128",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.3:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "D10C8CD0-5137-4669-BB00-B491FF0EA4F0",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.4:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "8AE0E37F-E5E3-4BF1-A619-D7D13F65A1EB",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.5:*:*:*:*:pcf_tiles:*:*",
                  "match_criteria_id": "D81CAB44-10C5-411C-BF43-42257A1517D6",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.0",
            "affected_versions_last": "1.7.0"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.1:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.0.1",
            "affected_versions_last": "1.7.0.1"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.2:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.0.2",
            "affected_versions_last": "1.7.0.2"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.3:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.0.3",
            "affected_versions_last": "1.7.0.3"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.0.4:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.0.4",
            "affected_versions_last": "1.7.0.4"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.1:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.1",
            "affected_versions_last": "1.7.1"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.2:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.2",
            "affected_versions_last": "1.7.2"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.3:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.3",
            "affected_versions_last": "1.7.3"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.4:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.4",
            "affected_versions_last": "1.7.4"
          },
          {
            "criteria": "cpe:2.3:a:vmware:pivotal_software_mysql:1.7.5:*:*:*:*:pcf_tiles:*:*",
            "vendor": "vmware",
            "product": "pivotal_software_mysql",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.7.5",
            "affected_versions_last": "1.7.5"
          }
        ],
        "cwe": [
          {
            "id": 532,
            "owasptop10_2021": "A09 Security Logging and Monitoring Failures",
            "name": "Insertion of Sensitive Information into Log File",
            "description": "The product writes sensitive information to a log file.",
            "capec_id": [
              215
            ],
            "scope": [
              "Confidentiality"
            ],
            "impact": [
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.01403,
          "percentile": 0.71385,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [CVSS v2: Low Exploitability Score](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-exploitability-score/)
- [KEV Remediation Due in November 2021](/reference/vulnerability/search/examples/cisa-action-due/)
- [CVSS v3.0: Low Impact Score](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-impact-score/)
- [CVEs Published in December 2021](/reference/vulnerability/search/examples/published/)
- [CVSS v3.1: Hard to Exploit](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-exploitability-score/)
- [CVSS 4.0: Base Score 9.0 to 9.9](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-base-score/)
