Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
primekey ejbca vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-34831
An issue exists in Keyfactor PrimeKey EJBCA prior to 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an identifie...
Primekey Ejbca
6.1
CVSSv3
CVE-2020-11626
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets.
Primekey Ejbca
8.8
CVSSv3
CVE-2020-11627
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
Primekey Ejbca
7.2
CVSSv3
CVE-2020-11629
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save uploaded test certificates to the server. An attacker who has gain...
Primekey Ejbca
9.8
CVSSv3
CVE-2020-11630
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized.
Primekey Ejbca
6.5
CVSSv3
CVE-2020-11631
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of other bugs. This follow-on exploitation can lead to privilege escalation and remote code execution. (This i...
Primekey Ejbca
2.3
CVSSv3
CVE-2021-40089
An issue exists in PrimeKey EJBCA prior to 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this sett...
Primekey Ejbca
7.3
CVSSv3
CVE-2020-25276
An issue exists in PrimeKey EJBCA 6.x and 7.x prior to 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only affect a system that has EST configured, uses client certificates to au...
Primekey Ejbca
5.3
CVSSv3
CVE-2020-11628
An issue exists in EJBCA prior to 6.15.2.6 and 7.x prior to 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client. (EJBCA&...
Primekey Ejbca
2.2
CVSSv3
CVE-2021-40086
An issue exists in PrimeKey EJBCA prior to 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from direct view, checking the page sou...
Primekey Ejbca
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »