Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. One Identity

One Identity

enriched
Identity & Access ManagementPassword ManagementSIEM

Represented by Exclusive Networks ↗

oneidentity.com ↗ · required email domain for this vendor's users

Do you work at One Identity?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on One Identity's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of One Identity we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 6 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Limited

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters location not disclosed on their site
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 1 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 19 published CVE(s) — a public disclosure record exists
    • 4 rated critical
  • Not checked

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 0 of 3

    We have not checked what this vendor discloses publicly yet.

    Nothing checked here yet — this is not a mark against One Identity.

  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against One Identity.

Data coverage: 15/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness25/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 25

IntegrationsUI-12 — integration graphDetected from this vendor's own published integration/partner pages by the enrichment loop — each entry links the exact page it was found on. Directional: "integrates with" is claimed by this vendor; "integrated by" is claimed by the other vendor's site. Coverage grows as the scan progresses.

10 detected

Integrated by: Cakewalk, Delinea, Devolutions, FusionAuth, Mesh Security, Operant AI, Readibots, Seceon Inc, Tenable, UncommonX

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

Manages AD, Entra ID & M365 with delegation, automation & least privilege AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

Product screenshots (2)

from their products
One Identity Password ManagerautoOne Identity Identity Managerauto

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL20182019202020212022202320242025CVE-2025-59363 · HIGH 7.7 · 2025-09-14CVE-2025-56689 · MEDIUM 4.6 · 2025-09-03CVE-2025-52924 · MEDIUM 4.0 · 2025-07-19CVE-2025-27582 · HIGH 7.6 · 2025-07-14CVE-2025-52925 · MEDIUM 5.0 · 2025-07-02CVE-2024-56404 · CRITICAL 9.9 · 2025-01-24CVE-2024-40595 · MEDIUM 5.3 · 2024-10-24CVE-2024-45488 · CRITICAL 9.8 · 2024-08-30CVE-2023-51772 · HIGH 8.8 · 2023-12-25CVE-2023-48654 · CRITICAL 9.8 · 2023-12-25CVE-2023-4003 · HIGH 7.6 · 2023-09-27CVE-2023-41890 · HIGH 7.5 · 2023-09-19CVE-2022-38725 · HIGH 7.5 · 2023-01-23CVE-2020-7962 · MEDIUM 5.3 · 2020-11-14CVE-2019-13497 · MEDIUM 6.5 · 2019-11-04CVE-2019-13496 · HIGH 8.1 · 2019-11-04CVE-2019-13498 · HIGH 7.4 · 2019-07-29CVE-2019-11268 · MEDIUM 4.3 · 2019-07-11CVE-2017-6553 · CRITICAL 9.8 · 2017-04-29

Known CVEs (19)About this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-59363 ↗HIGH 7.72025

    In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),

  • CVE-2025-56689 ↗MEDIUM 4.62025

    One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker…

  • CVE-2025-52924 ↗MEDIUM 4.02025

    In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.

  • CVE-2025-27582 ↗HIGH 7.62025

    The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser use…

  • CVE-2025-52925 ↗MEDIUM 5.02025

    In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

  • CVE-2024-56404 ↗CRITICAL 9.92025

    In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected.

  • CVE-2024-40595 ↗MEDIUM 5.32024

    An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtai…

  • CVE-2024-45488 ↗CRITICAL 9.82024

    One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). Th…

  • CVE-2023-51772 ↗HIGH 8.82023

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium ba…

  • CVE-2023-48654 ↗CRITICAL 9.82023

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium ba…

  • CVE-2023-4003 ↗HIGH 7.62023

    One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution wi…

  • CVE-2023-41890 ↗HIGH 7.52023

    Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider. Prior to versions 1.0.3 and 2.9.2, when a response is processed, the issue…

  • CVE-2022-38725 ↗HIGH 7.52023

    An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or netw…

  • CVE-2020-7962 ↗MEDIUM 5.32020

    An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response c…

  • CVE-2019-13497 ↗MEDIUM 6.52019

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

  • CVE-2019-13496 ↗HIGH 8.12019

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a succ…

  • CVE-2019-13498 ↗HIGH 7.42019

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

  • CVE-2019-11268 ↗MEDIUM 4.32019

    Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading …

  • CVE-2017-6553 ↗CRITICAL 9.82017

    Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory c…

Competitors (12)

full alternatives comparison →
1PasswordAkeyless SecurityAvatierDBAPP SecurityDeepnet SecurityEvidianGuruculHappiest MindsKeeper SecurityMy1LoginSecurdenSecurity Weaver

Products (5)

SIEM

1
  • syslog-ng Premium EditionAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Enterprise log management software for collecting and centralizing log data

Identity & Access Management

3
  • One Identity Active RolesAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Manages AD, Entra ID & M365 with delegation, automation & least privilege
  • One Identity Identity ManagerAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Enterprise IGA platform for user access governance and automated provisioning
  • One Identity SafeguardAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    PAM solution for securing privileged accounts and access across enterprises

Password Management

1
  • One Identity Password ManagerAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Self-service password reset and account unlock solution for end users