ITarian records
3 published records for vendor itarian.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-275 Permission Issues1
- CWE-358 Improperly Implemented Security Check for Standard1
- CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-25152No exploit | ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvalsitarian · on-premise · CWE-358 | High8.8 | — | 1.8% | Jun 9, 2022 |
31Monitor | CVE-2022-25153No exploit | ITarian - Local privilege escalation in Endpoint Manager agent on Windowsitarian · endpoint manager communication client · CWE-275 | High7.8 | — | 0.3% | Jun 9, 2022 |
30Monitor | CVE-2022-25151No exploit | ITarian - Session cookie not protected by HttpOnly flagitarian · on-premise · CWE-614 | High7.5 | — | 0.8% | Jun 9, 2022 |
- CVE-2022-2515236Monitor
ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvals
HighCVSS 8.8No exploitEPSS 2%itarian · on-premiseJun 9, 2022
- CVE-2022-2515331Monitor
ITarian - Local privilege escalation in Endpoint Manager agent on Windows
HighCVSS 7.8No exploitEPSS 0%itarian · endpoint manager communication clientJun 9, 2022
- CVE-2022-2515130Monitor
ITarian - Session cookie not protected by HttpOnly flag
HighCVSS 7.5No exploitEPSS 1%itarian · on-premiseJun 9, 2022