CVE-2024-9470
- EPSS 0.2%
- Veröffentlicht 09.10.2024 17:15:20
- Zuletzt bearbeitet 10.10.2024 12:51:56
A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.
CVE-2023-3282
- EPSS 0.03%
- Veröffentlicht 08.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:16:55
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the e...
CVE-2023-0003
- EPSS 1.05%
- Veröffentlicht 08.02.2023 18:15:11
- Zuletzt bearbeitet 13.02.2025 17:15:52
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
CVE-2022-0031
- EPSS 0.08%
- Veröffentlicht 09.11.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:37:51
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
CVE-2022-0027
- EPSS 0.29%
- Veröffentlicht 11.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:50
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, inc...
CVE-2022-0020
- EPSS 1.15%
- Veröffentlicht 10.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:37:50
A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web int...
CVE-2021-3049
- EPSS 0.11%
- Veröffentlicht 08.09.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:20:50
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are n...
CVE-2021-3051
- EPSS 0.14%
- Veröffentlicht 08.09.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:20:51
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and...
CVE-2021-3044
- EPSS 0.36%
- Veröffentlicht 22.06.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:49
An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR...
CVE-2021-3034
- EPSS 0.03%
- Veröffentlicht 10.03.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:20:48
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during...