Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. SPHERE/
  3. SPHERE Identity Intelligence

SPHERE Identity Intelligence

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 19 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Identity intelligence platform for visibility & remediation across AD, PAM & data

by SPHERE · sphereco.com · source ↗

Known CVEs (19)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2020-16988 ↗MEDIUM 6.92020

    Azure Sphere Elevation of Privilege Vulnerability

  • CVE-2020-16987 ↗HIGH 7.32020

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2020-16986 ↗MEDIUM 6.22020

    Azure Sphere Denial of Service Vulnerability

  • CVE-2020-16985 ↗MEDIUM 6.22020

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2020-16984 ↗HIGH 7.32020

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2020-16983 ↗MEDIUM 5.72020

    Azure Sphere Tampering Vulnerability

  • CVE-2020-16982 ↗MEDIUM 6.12020

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2020-16981 ↗MEDIUM 6.12020

    Azure Sphere Elevation of Privilege Vulnerability

  • CVE-2020-16970 ↗HIGH 8.12020

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2020-26084 ↗MEDIUM 6.52020

    A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device. The vulnerability is…

  • CVE-2020-16247 ↗MEDIUM 6.82020

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

  • CVE-2020-16212 ↗MEDIUM 6.82020

    In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. T…

  • CVE-2018-12475 ↗MEDIUM 6.52020

    A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against…

  • CVE-2020-7523 ↗HIGH 7.82020

    Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Seri…

  • CVE-2019-4314 ↗HIGH 7.52019

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. IBM X-Force ID: 1610141.

  • CVE-2019-15041 ↗MEDIUM 6.12019

    JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.

  • CVE-2018-7837 ↗HIGH 7.52018

    An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside…

  • CVE-2010-4541 ↗HIGH 9.32011

    Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service …

  • CVE-2002-0406 ↗MEDIUM 5.02002

    Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server without providing login credentials, which preven…

Materials

10

Datasheets

  • Solution Brief SPHEREboard Accounts ↗
  • Solution Brief SPHEREboard For Data ↗
  • Solution Brief Intelligent Discovery 2.0 ↗
  • Sphere CS SPHEREboard SecureAD ↗
  • Solution Brief Intelligent Discovery 1 1 ↗
  • Solution Brief Simplify ISO And NIST Compliance With SPHEREboard ↗
  • Solution Brief SPHEREboard SecureAD ↗
  • SB SPHEREboard For CyberArk PAM 1 ↗

Case studies

  • Case Study JetBlue ↗
  • SPHERE Case Study Unstructured Data ↗

Other Identity & Access Management products

see all →
  • 1Password Extended Access Management · 1Password
  • AD Guardian Cloud · CionSystems
  • ARCON Privileged Access Management · ARCON
  • Abbey Labs · Abbey Labs
  • Aceiss · Aceiss
  • Active Directory Permissions Analyzer · Paramount Defenses
  • Adaptive MFA · Okta
  • Adaxes · softerra adaxes