Haloservicesolutions develops HaloITSM, an IT service management platform whose disclosed vulnerabilities center on application-layer input handling and access control, with recurring issues including cross-site scripting, incorrect authorization, and weak password recovery mechanisms. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haloservicesolutions over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6202CRITICAL HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arb | Aug 6, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-6203HIGH HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email ad | Aug 6, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-6200MEDIUM HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user a | Aug 6, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-6201MEDIUM HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive | Aug 6, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haloservicesolutions.
Media articles that mention a CVE ID that affects a product developed by Haloservicesolutions — matched by CVE ID, not by vendor name.