Vulnerabilities
Vulnerable Software
Tribe29:  Security Vulnerabilities
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
CVSS Score
8.8
EPSS Score
0.001
Published
2024-01-12
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVSS Score
8.8
EPSS Score
0.001
Published
2024-01-12
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVSS Score
8.8
EPSS Score
0.0
Published
2024-01-12
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.
CVSS Score
3.3
EPSS Score
0.001
Published
2023-11-27
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
CVSS Score
8.8
EPSS Score
0.006
Published
2023-08-10
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
CVSS Score
4.3
EPSS Score
0.002
Published
2023-05-17
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
CVSS Score
8.3
EPSS Score
0.005
Published
2023-05-17
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-05-15
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
CVSS Score
6.1
EPSS Score
0.004
Published
2023-04-20
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
CVSS Score
8.8
EPSS Score
0.002
Published
2023-04-18


Contact Us

Shodan ® - All rights reserved