Vulnerabilities > Oneidentity > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-25 CVE-2023-51772 Insufficient Session Expiration vulnerability in Oneidentity Password Manager
One Identity Password Manager before 5.13.1 allows Kiosk Escape.
network
low complexity
oneidentity CWE-613
8.8
2023-01-23 CVE-2022-38725 Integer Overflow or Wraparound vulnerability in Oneidentity Syslog-Ng and Syslog-Ng Store BOX
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function.
network
low complexity
oneidentity CWE-190
7.5
2020-06-29 CVE-2020-8019 Unspecified vulnerability in Oneidentity Syslog-Ng
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server for SAP 12-SP1; openSUSE Backports SLE-15-SP1, openSUSE Leap 15.1 allowed local attackers controlling the user news to escalate their privileges to root.
local
low complexity
oneidentity
7.8
2019-11-04 CVE-2019-13496 Improper Validation of Integrity Check Value vulnerability in Oneidentity Cloud Access Manager
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.
network
high complexity
oneidentity CWE-354
8.1
2019-07-29 CVE-2019-13498 Cleartext Transmission of Sensitive Information vulnerability in Oneidentity Cloud Access Manager 8.1.3
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks.
network
high complexity
oneidentity CWE-319
7.4