Skip to main content

Vendor archive

oneidentity CVEs

Beta · best-effort

14 CVEs tagged to vendor oneidentity2 Critical, 8 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-51772

Published Dec 25, 2023

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It l…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48654

Published Dec 25, 2023

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It l…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-4003

Published Sep 27, 2023

One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. C…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7962

Published Nov 13, 2020

An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based o…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13496

Published Nov 4, 2019

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13498

Published Jul 29, 2019

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1951

Published Jul 11, 2011

lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5110

Published Nov 17, 2008

syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is pr…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1200

Published Oct 28, 2002

Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1