Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. One Identity/
  3. syslog-ng Premium Edition

syslog-ng Premium Edition

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 19 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Enterprise log management software for collecting and centralizing log data

by One Identity · oneidentity.com · source ↗

Known CVEs (19)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-59363 ↗HIGH 7.72025

    In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),

  • CVE-2025-56689 ↗MEDIUM 4.62025

    One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker…

  • CVE-2025-52924 ↗MEDIUM 4.02025

    In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.

  • CVE-2025-27582 ↗HIGH 7.62025

    The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser use…

  • CVE-2025-52925 ↗MEDIUM 5.02025

    In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

  • CVE-2024-56404 ↗CRITICAL 9.92025

    In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected.

  • CVE-2024-40595 ↗MEDIUM 5.32024

    An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtai…

  • CVE-2024-45488 ↗CRITICAL 9.82024

    One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). Th…

  • CVE-2023-51772 ↗HIGH 8.82023

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium ba…

  • CVE-2023-48654 ↗CRITICAL 9.82023

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium ba…

  • CVE-2023-4003 ↗HIGH 7.62023

    One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution wi…

  • CVE-2023-41890 ↗HIGH 7.52023

    Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider. Prior to versions 1.0.3 and 2.9.2, when a response is processed, the issue…

  • CVE-2022-38725 ↗HIGH 7.52023

    An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or netw…

  • CVE-2020-7962 ↗MEDIUM 5.32020

    An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response c…

  • CVE-2019-13497 ↗MEDIUM 6.52019

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

  • CVE-2019-13496 ↗HIGH 8.12019

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a succ…

  • CVE-2019-13498 ↗HIGH 7.42019

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

  • CVE-2019-11268 ↗MEDIUM 4.32019

    Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading …

  • CVE-2017-6553 ↗CRITICAL 9.82017

    Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory c…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other SIEM products

see all →
  • Abstract Security Platform · Abstract Security
  • AgileBlue Security Information and Event Management · AgileBlue
  • Anomali Unified Security Data Lake · Anomali
  • Anrita Cyber Defense · Zeronsec
  • Antiy Situational Awareness Platform · Antiy Labs
  • Auguria · Auguria
  • Autonomous Threat Sweeper · Securonix
  • Axoflow Platform · Axoflow