Записи OneIdentity
15 опубликованных записей вендора oneidentity.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 53,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-190 Integer Overflow or Wraparound1
- CWE-203 Observable Discrepancy1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-295 Improper Certificate Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-48654Эксплойта нет | One Identity Password Manager before 5.13.1 allows Kiosk Escape.oneidentity · password manager | Критическая9,8 | — | 1,0 % | 25 дек. 2023 г. |
38Наблюдать | CVE-2008-5110Эксплойта нет | syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail.oneidentity · syslog-ng | Критическая9,3 | — | 2,2 % | 17 нояб. 2008 г. |
35Наблюдать | CVE-2023-51772Эксплойта нет | One Identity Password Manager before 5.13.1 allows Kiosk Escape.oneidentity · password manager · CWE-613 | Высокая8,8 | — | 0,5 % | 25 дек. 2023 г. |
32Наблюдать | CVE-2002-1200Эксплойта нет | Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size ofoneidentity · syslog-ng · CWE-119 | Высокая7,5 | — | 5,6 % | 28 окт. 2002 г. |
32Наблюдать | CVE-2019-13496Proof of concept | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defendoneidentity · cloud access manager · CWE-354 | Высокая8,1 | — | 0,8 % | 4 нояб. 2019 г. |
31Наблюдать | CVE-2022-38725Proof of concept | An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service vioneidentity · syslog-ng · CWE-190 | Высокая7,5 | — | 2,4 % | 23 янв. 2023 г. |
31Наблюдать | CVE-2020-8019Эксплойта нет | syslog-ng: Local privilege escalation from new to root in %postsuse · linux enterprise debuginfo · CWE-61 | Высокая7,8 | — | 0,5 % | 29 июн. 2020 г. |
30Наблюдать | CVE-2024-47619Эксплойта нет | tranport: TLS host name wildcard matching too laxoneidentity · syslog-ng · CWE-295 | Высокая7,5 | — | 0,4 % | 7 мая 2025 г. |
29Наблюдать | CVE-2019-13498Proof of concept | One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacksoneidentity · cloud access manager · CWE-319 | Высокая7,4 | — | 1,2 % | 29 июл. 2019 г. |
27Наблюдать | CVE-2023-4003Эксплойта нет | One Identity Password Manager version 5.9.7.1 - Unauthenticated physical access privilege escalationoneidentity · password manager · CWE-250 | Средняя6,8 | — | 0,5 % | 27 сент. 2023 г. |
27Наблюдать | CVE-2011-0343Эксплойта нет | Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes sfreebsd · freebsd · CWE-264 | Средняя6,9 | — | 0,4 % | 28 янв. 2011 г. |
26Наблюдать | CVE-2019-13497Proof of concept | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.oneidentity · cloud access manager · CWE-352 | Средняя6,5 | — | 0,7 % | 4 нояб. 2019 г. |
21Наблюдать | CVE-2020-7962Эксплойта нет | An issue was discovered in One Identity Password Manager 5.8.oneidentity · password manager · CWE-203 | Средняя5,3 | — | 0,9 % | 13 нояб. 2020 г. |
21Наблюдать | CVE-2024-40595Эксплойта нет | An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTSCWE-319 | Средняя5,3 | — | 0,2 % | 24 окт. 2024 г. |
18Наблюдать | CVE-2011-1951Эксплойта нет | lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allowspcre · pcre · CWE-399 | Средняя4,3 | — | 2,5 % | 11 июл. 2011 г. |
- CVE-2023-4865439Наблюдать
One Identity Password Manager before 5.13.1 allows Kiosk Escape.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oneidentity · password manager25 дек. 2023 г.
- CVE-2008-511038Наблюдать
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail.
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %oneidentity · syslog-ng17 нояб. 2008 г.
- CVE-2023-5177235Наблюдать
One Identity Password Manager before 5.13.1 allows Kiosk Escape.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %oneidentity · password manager25 дек. 2023 г.
- CVE-2002-120032Наблюдать
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %oneidentity · syslog-ng28 окт. 2002 г.
- CVE-2019-1349632Наблюдать
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defend
ВысокаяCVSS 8,1Proof of conceptEPSS 1 %oneidentity · cloud access manager4 нояб. 2019 г.
- CVE-2022-3872531Наблюдать
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service vi
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %oneidentity · syslog-ng23 янв. 2023 г.
- CVE-2020-801931Наблюдать
syslog-ng: Local privilege escalation from new to root in %post
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %suse · linux enterprise debuginfo29 июн. 2020 г.
- CVE-2024-4761930Наблюдать
tranport: TLS host name wildcard matching too lax
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %oneidentity · syslog-ng7 мая 2025 г.
- CVE-2019-1349829Наблюдать
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks
ВысокаяCVSS 7,4Proof of conceptEPSS 1 %oneidentity · cloud access manager29 июл. 2019 г.
- CVE-2023-400327Наблюдать
One Identity Password Manager version 5.9.7.1 - Unauthenticated physical access privilege escalation
СредняяCVSS 6,8Эксплойта нетEPSS 1 %oneidentity · password manager27 сент. 2023 г.
- CVE-2011-034327Наблюдать
Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes s
СредняяCVSS 6,9Эксплойта нетEPSS 0 %freebsd · freebsd28 янв. 2011 г.
- CVE-2019-1349726Наблюдать
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
СредняяCVSS 6,5Proof of conceptEPSS 1 %oneidentity · cloud access manager4 нояб. 2019 г.
- CVE-2020-796221Наблюдать
An issue was discovered in One Identity Password Manager 5.8.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %oneidentity · password manager13 нояб. 2020 г.
- CVE-2024-4059521Наблюдать
An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS
СредняяCVSS 5,3Эксплойта нетEPSS 0 %24 окт. 2024 г.
- CVE-2011-195118Наблюдать
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows
СредняяCVSS 4,3Эксплойта нетEPSS 2 %pcre · pcre11 июл. 2011 г.