Vulnerabilities > Itarian > Saas Service Desk

DATE CVE VULNERABILITY TITLE RISK
2022-06-09 CVE-2022-25151 Incorrect Permission Assignment for Critical Resource vulnerability in Itarian On-Premise and Saas Service Desk
Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag.
network
low complexity
itarian CWE-732
7.5
2022-06-09 CVE-2022-25152 Unspecified vulnerability in Itarian On-Premise and Saas Service Desk
The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures.
network
low complexity
itarian
critical
9.0