Show filters
611 Total Results
Displaying 71-80 of 611
Sort by:
Attacker Value
Unknown
CVE-2024-35255
Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-3319
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.
0
Attacker Value
Unknown
CVE-2024-3318
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ attribute, which in turn allowed the user to access files uploaded for other sources.
0
Attacker Value
Unknown
CVE-2024-3317
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
0
Attacker Value
Unknown
CVE-2023-7240
Disclosure Date: May 07, 2024 (last updated May 08, 2024)
An improper authorization level has been detected in the login panel. It may lead to
unauthenticated Server Side Request Forgery and allows to perform open services
enumeration. Server makes query to provided server (Server IP/DNS field) and is
triggering connection to arbitrary address.
0
Attacker Value
Unknown
CVE-2024-24910
Disclosure Date: April 18, 2024 (last updated April 19, 2024)
A local attacker can escalate privileges on affected Check Point ZoneAlarm Extreme Security NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.
0
Attacker Value
Unknown
CVE-2024-29992
Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Azure Identity Library for .NET Information Disclosure Vulnerability
0
Attacker Value
Unknown
CVE-2024-20368
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.
0
Attacker Value
Unknown
CVE-2024-20332
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To successfully exploit this vulnerability, the attacker would need valid Super Admin credentials.
0
Attacker Value
Unknown
CVE-2024-2228
Disclosure Date: March 22, 2024 (last updated April 02, 2024)
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
0