Jamf kayıtları
jamf üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-269 Improper Privilege Management1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-17076İstismar yok | An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1.jamf · jamf · CWE-502 | Kritik9,8 | — | %2,5 | 8 Oca 2020 |
40Planlayın | CVE-2021-39303İstismar yok | The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352.jamf · jamf · CWE-918 | Kritik9,8 | — | %1,7 | 12 Kas 2021 |
39İzleyin | CVE-2023-31224İstismar yok | There is broken access control during authentication in Jamf Pro Server before 10.46.1.jamf · jamf · CWE-287 | Kritik9,8 | — | %0,6 | 25 Ara 2023 |
35İzleyin | CVE-2021-40809İstismar yok | An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921.jamf · jamf · CWE-918 | Yüksek8,8 | — | %1,5 | 30 Kas 2021 |
35İzleyin | CVE-2018-10465İstismar yok | Jamf Pro 10.x before 10.3.0 has Incorrect Access Control.jamf · jamf | Yüksek8,8 | — | %1,2 | 7 Oca 2020 |
30İzleyin | CVE-2022-29564İstismar yok | Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastjamf · private access | Yüksek7,5 | — | %0,9 | 7 Haz 2022 |
30İzleyin | CVE-2019-9146İstismar yok | Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature tojamf · self service | Yüksek7,5 | — | %0,8 | 25 Şub 2019 |
29İzleyin | CVE-2024-4395İstismar yok | Lack of Client Validation in Jamf Compliance Editor's Helper Service May Result in Privilege Escalationjamf · jamf compliance editor · CWE-269 | Yüksek7,3 | — | %0,2 | 27 Haz 2024 |
27İzleyin | CVE-2012-4051Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Sujamf · casper suite · CWE-352 | Orta6,8 | — | %1,5 | 28 Eyl 2012 |
24İzleyin | CVE-2021-30125İstismar yok | Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.jamf · jamf · CWE-79 | Orta6,1 | — | %0,6 | 2 Nis 2021 |
24İzleyin | CVE-2021-35037İstismar yok | Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-prejamf · jamf · CWE-601 | Orta6,1 | — | %0,6 | 12 Tem 2021 |
- CVE-2019-1707640Planlayın
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1.
KritikCVSS 9,8İstismar yokEPSS %3jamf · jamf8 Oca 2020
- CVE-2021-3930340Planlayın
The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352.
KritikCVSS 9,8İstismar yokEPSS %2jamf · jamf12 Kas 2021
- CVE-2023-3122439İzleyin
There is broken access control during authentication in Jamf Pro Server before 10.46.1.
KritikCVSS 9,8İstismar yokEPSS %1jamf · jamf25 Ara 2023
- CVE-2021-4080935İzleyin
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921.
YüksekCVSS 8,8İstismar yokEPSS %1jamf · jamf30 Kas 2021
- CVE-2018-1046535İzleyin
Jamf Pro 10.x before 10.3.0 has Incorrect Access Control.
YüksekCVSS 8,8İstismar yokEPSS %1jamf · jamf7 Oca 2020
- CVE-2022-2956430İzleyin
Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrast
YüksekCVSS 7,5İstismar yokEPSS %1jamf · private access7 Haz 2022
- CVE-2019-914630İzleyin
Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to
YüksekCVSS 7,5İstismar yokEPSS %1jamf · self service25 Şub 2019
- CVE-2024-439529İzleyin
Lack of Client Validation in Jamf Compliance Editor's Helper Service May Result in Privilege Escalation
YüksekCVSS 7,3İstismar yokEPSS %0jamf · jamf compliance editor27 Haz 2024
- CVE-2012-405127İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Su
OrtaCVSS 6,8Kavram kanıtıEPSS %1jamf · casper suite28 Eyl 2012
- CVE-2021-3012524İzleyin
Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.
OrtaCVSS 6,1İstismar yokEPSS %1jamf · jamf2 Nis 2021
- CVE-2021-3503724İzleyin
Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-pre
OrtaCVSS 6,1İstismar yokEPSS %1jamf · jamf12 Tem 2021