Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jamf CRITICAL 9.8
CVE-2023-31224

There is broken access control during authentication in Jamf Pro Server before 10.46.1.

Fix: 10.47.0+
Fix from $2,300 2023-12-25
Private Access HIGH 7.5
CVE-2022-29564

Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, …

Fix: 2022-05-16+
Fix from $1,950 2022-06-07
Jamf HIGH 8.8
CVE-2021-40809

An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that …

Fix: 10.32.0+
Fix from $1,950 2021-12-01
Jamf CRITICAL 9.8
CVE-2021-39303

The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerabili…

Fix: 10.32.0+
Fix from $2,300 2021-11-12
Jamf MEDIUM 6.1
CVE-2021-35037

Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An…

Fix: 10.30.1+
Fix from $1,600 2021-07-12
Jamf MEDIUM 6.1
CVE-2021-30125

Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.

Fix: 10.28.0+
Fix from $1,600 2021-04-02
Jamf CRITICAL 9.8
CVE-2019-17076

An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial…

Fix: after 10.15.0
Fix from $2,300 2020-01-08
Jamf HIGH 8.8
CVE-2018-10465

Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jamf Pro had full access to endp…

Fix: 10.3.0+
Fix from $1,950 2020-01-07
Self Service HIGH 7.5
CVE-2019-9146

Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to insert "…

No fix yet
Fix from $1,950 2019-02-25
Casper Suite MEDIUM 6.8
CVE-2012-4051

Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite befor…

Fix: after 8.6
Fix from $1,600 2012-09-28