Show filters
611 Total Results
Displaying 71-80 of 611
Sort by:
Attacker Value
Unknown

CVE-2024-35255

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-3319

Disclosure Date: May 15, 2024 (last updated May 16, 2024)
An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.
0
Attacker Value
Unknown

CVE-2024-3318

Disclosure Date: May 15, 2024 (last updated May 16, 2024)
A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ attribute, which in turn allowed the user to access files uploaded for other sources.
0
Attacker Value
Unknown

CVE-2024-3317

Disclosure Date: May 15, 2024 (last updated May 16, 2024)
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
0
Attacker Value
Unknown

CVE-2023-7240

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
 An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to arbitrary address.
0
Attacker Value
Unknown

CVE-2024-24910

Disclosure Date: April 18, 2024 (last updated April 19, 2024)
A local attacker can escalate privileges on affected Check Point ZoneAlarm Extreme Security NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.
0
Attacker Value
Unknown

CVE-2024-29992

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Azure Identity Library for .NET Information Disclosure Vulnerability
0
Attacker Value
Unknown

CVE-2024-20368

Disclosure Date: April 03, 2024 (last updated April 04, 2024)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.
0
Attacker Value
Unknown

CVE-2024-20332

Disclosure Date: April 03, 2024 (last updated April 04, 2024)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To successfully exploit this vulnerability, the attacker would need valid Super Admin credentials.
0
Attacker Value
Unknown

CVE-2024-2228

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
0