Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
primekey ejbca vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-34831
An issue exists in Keyfactor PrimeKey EJBCA prior to 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an identifie...
Primekey Ejbca
436
VMScore
CVE-2021-40088
An issue exists in PrimeKey EJBCA prior to 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by ver...
Primekey Ejbca
383
VMScore
CVE-2020-11626
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets.
Primekey Ejbca
605
VMScore
CVE-2020-11627
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
Primekey Ejbca
578
VMScore
CVE-2020-11629
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save uploaded test certificates to the server. An attacker who has gain...
Primekey Ejbca
668
VMScore
CVE-2020-11630
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized.
Primekey Ejbca
445
VMScore
CVE-2020-11628
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client. (EJBCA&...
Primekey Ejbca
356
VMScore
CVE-2020-11631
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of other bugs. This follow-on exploitation can lead to privilege escalation and remote code execution. (This i...
Primekey Ejbca
356
VMScore
CVE-2020-28942
An issue exists in PrimeKey EJBCA prior to 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client certificates (for the RA, not the end user) to a limi...
Primekey Ejbca
312
VMScore
CVE-2021-40086
An issue exists in PrimeKey EJBCA prior to 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from direct view, checking the page sou...
Primekey Ejbca
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
XXE
CVE-2024-34490
SQL injection
CVE-2024-34488
CVE-2024-4507
CVE-2023-7028
CVE-2024-23187
TCP
CVE-2024-4439
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »