Show filters
42 Total Results
Displaying 21-30 of 42
Sort by:
Attacker Value
Unknown

CVE-2024-3367

Disclosure Date: April 16, 2024 (last updated December 21, 2024)
Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc
Attacker Value
Unknown

CVE-2024-28824

Disclosure Date: March 22, 2024 (last updated December 21, 2024)
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
Attacker Value
Unknown

CVE-2024-1742

Disclosure Date: March 22, 2024 (last updated December 21, 2024)
Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.
Attacker Value
Unknown

CVE-2024-0638

Disclosure Date: March 22, 2024 (last updated December 21, 2024)
Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
Attacker Value
Unknown

CVE-2024-0670

Disclosure Date: March 11, 2024 (last updated December 21, 2024)
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
Attacker Value
Unknown

CVE-2023-6740

Disclosure Date: January 12, 2024 (last updated July 24, 2024)
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
Attacker Value
Unknown

CVE-2023-6735

Disclosure Date: January 12, 2024 (last updated July 24, 2024)
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
Attacker Value
Unknown

CVE-2023-31211

Disclosure Date: January 12, 2024 (last updated July 24, 2024)
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
Attacker Value
Unknown

CVE-2023-31210

Disclosure Date: December 13, 2023 (last updated July 24, 2024)
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
Attacker Value
Unknown

CVE-2023-6251

Disclosure Date: November 24, 2023 (last updated July 24, 2024)
Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to delete user-messages for individual users.