OneIdentity kayıtları
oneidentity üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %53,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-190 Integer Overflow or Wraparound1
- CWE-203 Observable Discrepancy1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-295 Improper Certificate Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-48654İstismar yok | One Identity Password Manager before 5.13.1 allows Kiosk Escape.oneidentity · password manager | Kritik9,8 | — | %1,0 | 25 Ara 2023 |
38İzleyin | CVE-2008-5110İstismar yok | syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail.oneidentity · syslog-ng | Kritik9,3 | — | %2,2 | 17 Kas 2008 |
35İzleyin | CVE-2023-51772İstismar yok | One Identity Password Manager before 5.13.1 allows Kiosk Escape.oneidentity · password manager · CWE-613 | Yüksek8,8 | — | %0,5 | 25 Ara 2023 |
32İzleyin | CVE-2002-1200İstismar yok | Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size ofoneidentity · syslog-ng · CWE-119 | Yüksek7,5 | — | %5,6 | 28 Eki 2002 |
32İzleyin | CVE-2019-13496Kavram kanıtı | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defendoneidentity · cloud access manager · CWE-354 | Yüksek8,1 | — | %0,8 | 4 Kas 2019 |
31İzleyin | CVE-2022-38725Kavram kanıtı | An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service vioneidentity · syslog-ng · CWE-190 | Yüksek7,5 | — | %2,4 | 23 Oca 2023 |
31İzleyin | CVE-2020-8019İstismar yok | syslog-ng: Local privilege escalation from new to root in %postsuse · linux enterprise debuginfo · CWE-61 | Yüksek7,8 | — | %0,5 | 29 Haz 2020 |
30İzleyin | CVE-2024-47619İstismar yok | tranport: TLS host name wildcard matching too laxoneidentity · syslog-ng · CWE-295 | Yüksek7,5 | — | %0,4 | 7 May 2025 |
29İzleyin | CVE-2019-13498Kavram kanıtı | One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacksoneidentity · cloud access manager · CWE-319 | Yüksek7,4 | — | %1,2 | 29 Tem 2019 |
27İzleyin | CVE-2023-4003İstismar yok | One Identity Password Manager version 5.9.7.1 - Unauthenticated physical access privilege escalationoneidentity · password manager · CWE-250 | Orta6,8 | — | %0,5 | 27 Eyl 2023 |
27İzleyin | CVE-2011-0343İstismar yok | Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes sfreebsd · freebsd · CWE-264 | Orta6,9 | — | %0,4 | 28 Oca 2011 |
26İzleyin | CVE-2019-13497Kavram kanıtı | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.oneidentity · cloud access manager · CWE-352 | Orta6,5 | — | %0,7 | 4 Kas 2019 |
21İzleyin | CVE-2020-7962İstismar yok | An issue was discovered in One Identity Password Manager 5.8.oneidentity · password manager · CWE-203 | Orta5,3 | — | %0,9 | 13 Kas 2020 |
21İzleyin | CVE-2024-40595İstismar yok | An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTSCWE-319 | Orta5,3 | — | %0,2 | 24 Eki 2024 |
18İzleyin | CVE-2011-1951İstismar yok | lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allowspcre · pcre · CWE-399 | Orta4,3 | — | %2,5 | 11 Tem 2011 |
- CVE-2023-4865439İzleyin
One Identity Password Manager before 5.13.1 allows Kiosk Escape.
KritikCVSS 9,8İstismar yokEPSS %1oneidentity · password manager25 Ara 2023
- CVE-2008-511038İzleyin
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail.
KritikCVSS 9,3İstismar yokEPSS %2oneidentity · syslog-ng17 Kas 2008
- CVE-2023-5177235İzleyin
One Identity Password Manager before 5.13.1 allows Kiosk Escape.
YüksekCVSS 8,8İstismar yokEPSS %1oneidentity · password manager25 Ara 2023
- CVE-2002-120032İzleyin
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of
YüksekCVSS 7,5İstismar yokEPSS %6oneidentity · syslog-ng28 Eki 2002
- CVE-2019-1349632İzleyin
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defend
YüksekCVSS 8,1Kavram kanıtıEPSS %1oneidentity · cloud access manager4 Kas 2019
- CVE-2022-3872531İzleyin
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service vi
YüksekCVSS 7,5Kavram kanıtıEPSS %2oneidentity · syslog-ng23 Oca 2023
- CVE-2020-801931İzleyin
syslog-ng: Local privilege escalation from new to root in %post
YüksekCVSS 7,8İstismar yokEPSS %1suse · linux enterprise debuginfo29 Haz 2020
- CVE-2024-4761930İzleyin
tranport: TLS host name wildcard matching too lax
YüksekCVSS 7,5İstismar yokEPSS %0oneidentity · syslog-ng7 May 2025
- CVE-2019-1349829İzleyin
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks
YüksekCVSS 7,4Kavram kanıtıEPSS %1oneidentity · cloud access manager29 Tem 2019
- CVE-2023-400327İzleyin
One Identity Password Manager version 5.9.7.1 - Unauthenticated physical access privilege escalation
OrtaCVSS 6,8İstismar yokEPSS %1oneidentity · password manager27 Eyl 2023
- CVE-2011-034327İzleyin
Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes s
OrtaCVSS 6,9İstismar yokEPSS %0freebsd · freebsd28 Oca 2011
- CVE-2019-1349726İzleyin
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
OrtaCVSS 6,5Kavram kanıtıEPSS %1oneidentity · cloud access manager4 Kas 2019
- CVE-2020-796221İzleyin
An issue was discovered in One Identity Password Manager 5.8.
OrtaCVSS 5,3İstismar yokEPSS %1oneidentity · password manager13 Kas 2020
- CVE-2024-4059521İzleyin
An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS
OrtaCVSS 5,3İstismar yokEPSS %024 Eki 2024
- CVE-2011-195118İzleyin
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows
OrtaCVSS 4,3İstismar yokEPSS %2pcre · pcre11 Tem 2011