Skip to content
Noroxi

Jamf records

11 published records for vendor jamf.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

11 records
  • An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1.

    CriticalCVSS 9.8No exploitEPSS 3%

    jamf · jamfJan 8, 2020

  • The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352.

    CriticalCVSS 9.8No exploitEPSS 2%

    jamf · jamfNov 12, 2021

  • There is broken access control during authentication in Jamf Pro Server before 10.46.1.

    CriticalCVSS 9.8No exploitEPSS 1%

    jamf · jamfDec 25, 2023

  • An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921.

    HighCVSS 8.8No exploitEPSS 1%

    jamf · jamfNov 30, 2021

  • Jamf Pro 10.x before 10.3.0 has Incorrect Access Control.

    HighCVSS 8.8No exploitEPSS 1%

    jamf · jamfJan 7, 2020

  • Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrast

    HighCVSS 7.5No exploitEPSS 1%

    jamf · private accessJun 7, 2022

  • CVE-2019-9146
    30Monitor

    Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to

    HighCVSS 7.5No exploitEPSS 1%

    jamf · self serviceFeb 25, 2019

  • CVE-2024-4395
    29Monitor

    Lack of Client Validation in Jamf Compliance Editor's Helper Service May Result in Privilege Escalation

    HighCVSS 7.3No exploitEPSS 0%

    jamf · jamf compliance editorJun 27, 2024

  • CVE-2012-4051
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Su

    MediumCVSS 6.8Proof of conceptEPSS 1%

    jamf · casper suiteSep 28, 2012

  • Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.

    MediumCVSS 6.1No exploitEPSS 1%

    jamf · jamfApr 2, 2021

  • Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-pre

    MediumCVSS 6.1No exploitEPSS 1%

    jamf · jamfJul 12, 2021