Jamf records
11 published records for vendor jamf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-269 Improper Privilege Management1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-17076No exploit | An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1.jamf · jamf · CWE-502 | Critical9.8 | — | 2.5% | Jan 8, 2020 |
40Plan | CVE-2021-39303No exploit | The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352.jamf · jamf · CWE-918 | Critical9.8 | — | 1.7% | Nov 12, 2021 |
39Monitor | CVE-2023-31224No exploit | There is broken access control during authentication in Jamf Pro Server before 10.46.1.jamf · jamf · CWE-287 | Critical9.8 | — | 0.6% | Dec 25, 2023 |
35Monitor | CVE-2021-40809No exploit | An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921.jamf · jamf · CWE-918 | High8.8 | — | 1.5% | Nov 30, 2021 |
35Monitor | CVE-2018-10465No exploit | Jamf Pro 10.x before 10.3.0 has Incorrect Access Control.jamf · jamf | High8.8 | — | 1.2% | Jan 7, 2020 |
30Monitor | CVE-2022-29564No exploit | Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastjamf · private access | High7.5 | — | 0.9% | Jun 7, 2022 |
30Monitor | CVE-2019-9146No exploit | Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature tojamf · self service | High7.5 | — | 0.8% | Feb 25, 2019 |
29Monitor | CVE-2024-4395No exploit | Lack of Client Validation in Jamf Compliance Editor's Helper Service May Result in Privilege Escalationjamf · jamf compliance editor · CWE-269 | High7.3 | — | 0.2% | Jun 27, 2024 |
27Monitor | CVE-2012-4051Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Sujamf · casper suite · CWE-352 | Medium6.8 | — | 1.5% | Sep 28, 2012 |
24Monitor | CVE-2021-30125No exploit | Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.jamf · jamf · CWE-79 | Medium6.1 | — | 0.6% | Apr 2, 2021 |
24Monitor | CVE-2021-35037No exploit | Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-prejamf · jamf · CWE-601 | Medium6.1 | — | 0.6% | Jul 12, 2021 |
- CVE-2019-1707640Plan
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1.
CriticalCVSS 9.8No exploitEPSS 3%jamf · jamfJan 8, 2020
- CVE-2021-3930340Plan
The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352.
CriticalCVSS 9.8No exploitEPSS 2%jamf · jamfNov 12, 2021
- CVE-2023-3122439Monitor
There is broken access control during authentication in Jamf Pro Server before 10.46.1.
CriticalCVSS 9.8No exploitEPSS 1%jamf · jamfDec 25, 2023
- CVE-2021-4080935Monitor
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921.
HighCVSS 8.8No exploitEPSS 1%jamf · jamfNov 30, 2021
- CVE-2018-1046535Monitor
Jamf Pro 10.x before 10.3.0 has Incorrect Access Control.
HighCVSS 8.8No exploitEPSS 1%jamf · jamfJan 7, 2020
- CVE-2022-2956430Monitor
Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrast
HighCVSS 7.5No exploitEPSS 1%jamf · private accessJun 7, 2022
- CVE-2019-914630Monitor
Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to
HighCVSS 7.5No exploitEPSS 1%jamf · self serviceFeb 25, 2019
- CVE-2024-439529Monitor
Lack of Client Validation in Jamf Compliance Editor's Helper Service May Result in Privilege Escalation
HighCVSS 7.3No exploitEPSS 0%jamf · jamf compliance editorJun 27, 2024
- CVE-2012-405127Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Su
MediumCVSS 6.8Proof of conceptEPSS 1%jamf · casper suiteSep 28, 2012
- CVE-2021-3012524Monitor
Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.
MediumCVSS 6.1No exploitEPSS 1%jamf · jamfApr 2, 2021
- CVE-2021-3503724Monitor
Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-pre
MediumCVSS 6.1No exploitEPSS 1%jamf · jamfJul 12, 2021