Oneidentity maintains a focused portfolio of identity and access management products, including the widely deployed syslog-ng log management platform and cloud access control solutions, serving a security-conscious user base with elevated baseline expectations. Its vulnerability profile shows a moderate tendency toward serious-severity outcomes and clusters around characteristic authentication, credential handling, and protocol-security weakness classes including cleartext transmission of sensitive data, cross-site request forgery, and certificate validation issues that reflect the access-control and data-protection demands of identity platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oneidentity over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48654CRITICAL One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It la | Dec 25, 2023 | 9.8 | 27 | NO | NO |
CVE-2008-5110HIGH syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is pre | Nov 17, 2008 | 9.3 | 27 | NO | NO |
CVE-2020-8019HIGH A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux E | Jun 29, 2020 | 7.8 | 26 | NO | NO |
CVE-2022-38725HIGH An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandle | Jan 23, 2023 | 7.5 | 25 | NO | NO |
CVE-2019-13498HIGH One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4. | Jul 29, 2019 | 7.4 | 25 | NO | NO |
CVE-2019-13496HIGH One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML | Nov 4, 2019 | 8.1 | 24 | NO | NO |
CVE-2023-51772HIGH One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It la | Dec 25, 2023 | 8.8 | 23 | NO | NO |
CVE-2025-27582HIGH The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within t | Jul 14, 2025 | 7.6 | 22 | NO | NO |
CVE-2024-47619HIGH syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to | May 7, 2025 | 7.5 | 22 | NO | NO |
CVE-2002-1200HIGH Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are e | Oct 28, 2002 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oneidentity.
Media articles that mention a CVE ID that affects a product developed by Oneidentity — matched by CVE ID, not by vendor name.