Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Checkmk HIGH 8.8
CVE-2023-6156

Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbit…

Mitigation only
Fix from $1,950 2023-11-22
Checkmk HIGH 8.8
CVE-2023-6157

Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatu…

Mitigation only
Fix from $1,950 2023-11-22
Checkmk HIGH 8.8
CVE-2023-31209

Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authe…

Fix: 2.0.0+
Fix from $1,950 2023-08-10
Checkmk MEDIUM 6.1
CVE-2023-23548

Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.

Fix: after 1.6.0
Fix from $1,600 2023-08-01
Checkmk HIGH 8.8
CVE-2023-31208

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary live…

Fix: 2.0.0+
Fix from $1,950 2023-05-17
Checkmk MEDIUM 5.5
CVE-2023-31207

Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret…

Mitigation only
Fix from $1,600 2023-05-02
Checkmk HIGH 8.8
CVE-2022-46302

Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations…

Mitigation only
Fix from $1,950 2023-04-20
Checkmk MEDIUM 5.3
CVE-2023-1768

Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric e…

Patch available
Fix from $1,600 2023-04-04
Checkmk MEDIUM 5.4
CVE-2023-22288

HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject maliciou…

Fix: 2.0.0+
Fix from $1,600 2023-03-20
Checkmk CRITICAL 9.8
CVE-2022-48317

Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use ex…

Mitigation only
Fix from $2,300 2023-02-20
Checkmk HIGH 8.8
CVE-2022-46836

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an atta…

No fix yet
Fix from $1,950 2023-02-20
Checkmk HIGH 7.8
CVE-2022-47909

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions o…

No fix yet
Fix from $1,950 2023-02-20
Checkmk HIGH 7.5
CVE-2022-46303

Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Mana…

Mitigation only
Fix from $1,950 2023-02-20
Checkmk MEDIUM 5.5
CVE-2022-48319

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0…

Mitigation only
Fix from $1,600 2023-02-20
Checkmk MEDIUM 5.3
CVE-2022-48318

No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended informa…

Mitigation only
Fix from $1,600 2023-02-20
Checkmk HIGH 7.8
CVE-2022-43440

Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows t…

Fix: 1.6.0+
Fix from $1,950 2023-02-09
Checkmk HIGH 8.1
CVE-2023-0284

Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Chec…

Fix: 2.0.0+
Fix from $1,950 2023-01-26
Checkmk HIGH 7.8
CVE-2022-33912

A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise ed…

Mitigation only
Fix from $1,950 2022-06-17
Checkmk MEDIUM 6.7
CVE-2022-31258

In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.

Fix: 1.6.0+
Fix from $1,600 2022-05-20
Checkmk HIGH 8.8
CVE-2021-40904

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default),…

Fix: 1.6.0+
Fix from $1,950 2022-03-25
Checkmk HIGH 8.8
CVE-2021-40905

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which …

Fix: 2.0.0+
Fix from $1,950 2022-03-25
Checkmk MEDIUM 6.1
CVE-2021-40906

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. Thi…

Fix: 1.6.0+
Fix from $1,600 2022-03-25
Checkmk MEDIUM 5.4
CVE-2022-24565

Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias o…

Mitigation only
Fix from $1,600 2022-02-24
Checkmk MEDIUM 5.4
CVE-2022-24566

In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when sh…

Mitigation only
Fix from $1,600 2022-02-24
Checkmk MEDIUM 6.1
CVE-2022-24564

Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML …

Patch available
Fix from $1,600 2022-02-21
Checkmk MEDIUM 5.4
CVE-2020-28919

A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary Jav…

Patch available
Fix from $1,600 2022-01-15
Checkmk MEDIUM 5.4
CVE-2021-36563

The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an at…

Fix: after 2.0.0
Fix from $1,600 2021-07-26
Checkmk HIGH 7.8
CVE-2020-24908

Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local direc…

Fix: 1.6.0+
Fix from $1,950 2021-02-19
Checkmk MEDIUM 5.9
CVE-2017-14955EPSS 12%

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to…

No fix yet
Fix from $1,600 2017-10-02