Search Results (16 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-38649 1 Microsoft 12 Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics and 9 more 2025-10-22 7 High
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38648 1 Microsoft 12 Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics and 9 more 2025-10-22 7.8 High
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38647 1 Microsoft 12 Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics and 9 more 2025-10-22 9.8 Critical
Open Management Infrastructure Remote Code Execution Vulnerability
CVE-2021-38645 1 Microsoft 12 Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics and 9 more 2025-10-22 7.8 High
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2023-36043 1 Microsoft 1 System Center Operations Manager 2025-10-08 6.5 Medium
Open Management Infrastructure Information Disclosure Vulnerability
CVE-2025-27743 1 Microsoft 5 System Center Data Protection Manager, System Center Operations Manager, System Center Orchestrator and 2 more 2025-07-10 7.8 High
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
CVE-2022-33640 1 Microsoft 2 Open Management Infrastructure, System Center Operations Manager 2025-06-05 7.8 High
System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
CVE-2024-21334 1 Microsoft 2 Open Management Infrastructure, System Center Operations Manager 2025-05-03 9.8 Critical
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2024-21330 1 Microsoft 8 Azure Automation, Azure Automation Update Management, Azure Security Center and 5 more 2025-05-03 7.8 High
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
CVE-2015-2420 1 Microsoft 1 System Center Operations Manager 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "System Center Operations Manager Web Console XSS Vulnerability."
CVE-2013-0009 1 Microsoft 1 System Center Operations Manager 2025-04-11 N/A
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
CVE-2013-0010 1 Microsoft 1 System Center Operations Manager 2025-04-11 N/A
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
CVE-2022-29149 1 Microsoft 10 Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics and 7 more 2025-01-02 7.8 High
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
CVE-2021-41352 1 Microsoft 1 System Center Operations Manager 2024-11-21 7.5 High
SCOM Information Disclosure Vulnerability
CVE-2021-1728 1 Microsoft 1 System Center Operations Manager 2024-11-21 8.8 High
System Center Operations Manager Elevation of Privilege Vulnerability
CVE-2020-1331 1 Microsoft 1 System Center Operations Manager 2024-11-21 5.4 Medium
A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'.