Lucene search

K

Management Agents Security Vulnerabilities

cve
cve

CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October...

7.5CVSS

8AI Score

0.732EPSS

2023-10-10 02:15 PM
2908
In Wild
cve
cve

CVE-2023-4801

An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to.....

7.5CVSS

7.3AI Score

0.001EPSS

2023-09-13 04:15 PM
13
cve
cve

CVE-2023-2818

An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are...

5.5CVSS

5.3AI Score

0.0004EPSS

2023-06-27 03:15 PM
10
cve
cve

CVE-2023-0511

Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to...

9.8CVSS

9.3AI Score

0.001EPSS

2023-02-28 05:15 PM
25
cve
cve

CVE-2023-0339

Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to...

9.8CVSS

9.3AI Score

0.001EPSS

2023-02-28 05:15 PM
27
2
cve
cve

CVE-2002-2422

Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error...

5.9AI Score

0.002EPSS

2022-10-03 04:23 PM
24
cve
cve

CVE-2022-25294

Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges. All versions prior to 7.12.1 are affected. Agents for MacOS and Linux and Cloud are unaffected....

7.8CVSS

7.7AI Score

0.0004EPSS

2022-03-10 05:47 PM
46
cve
cve

CVE-2021-27900

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. This enables a view-only user to change any configuration setting and delete any registered agents. All versions before 7.11.1 are...

8.1CVSS

7.9AI Score

0.001EPSS

2021-04-06 10:15 PM
43
4
cve
cve

CVE-2021-27899

The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-middle attack. All versions before 7.11.1 are...

7.4CVSS

7.3AI Score

0.002EPSS

2021-04-06 09:15 PM
35
4
cve
cve

CVE-2021-22159

Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25 as well as versions 7.3 and earlier is missing authentication for.....

7.8CVSS

7.7AI Score

0.0004EPSS

2021-01-26 08:15 PM
28
2
cve
cve

CVE-2012-2005

Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.8AI Score

0.002EPSS

2012-05-02 10:55 PM
20
cve
cve

CVE-2012-2006

Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown...

6.8AI Score

0.006EPSS

2012-05-02 10:55 PM
23
cve
cve

CVE-2012-2004

Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified...

6.8AI Score

0.016EPSS

2012-05-02 10:55 PM
26
cve
cve

CVE-2012-2003

Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown...

7.2AI Score

0.003EPSS

2012-05-02 10:55 PM
26
cve
cve

CVE-2010-4112

HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full...

6.2AI Score

0.006EPSS

2010-12-22 09:00 PM
20
cve
cve

CVE-2001-0728

Buffer overflow in Compaq Management Agents before 5.2, included in Compaq Web-enabled Management Software, allows local users to gain...

6.8AI Score

0.001EPSS

2002-03-09 05:00 AM
32
cve
cve

CVE-1999-1355

BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous...

7.3AI Score

0.003EPSS

2001-09-12 04:00 AM
20
cve
cve

CVE-2001-0374

The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access...

6.9AI Score

0.006EPSS

2001-06-18 04:00 AM
31
cve
cve

CVE-2001-0134

Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user...

7.8AI Score

0.007EPSS

2001-03-12 05:00 AM
26
cve
cve

CVE-1999-0771

The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot)...

7AI Score

0.076EPSS

2000-01-04 05:00 AM
21
cve
cve

CVE-1999-0772

Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port...

6.9AI Score

0.003EPSS

2000-01-04 05:00 AM
20