Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oneidentity

First CVE: Oct 28, 2002Active for: 24 yearsTotal CVEs: 15
28.5
VTI Score
Low

Oneidentity maintains a focused portfolio of identity and access management products, including the widely deployed syslog-ng log management platform and cloud access control solutions, serving a security-conscious user base with elevated baseline expectations. Its vulnerability profile shows a moderate tendency toward serious-severity outcomes and clusters around characteristic authentication, credential handling, and protocol-security weakness classes including cleartext transmission of sensitive data, cross-site request forgery, and certificate validation issues that reflect the access-control and data-protection demands of identity platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oneidentity over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2002
23 years ago
Most Recent CVE
Jul 14, 2025
375 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-48654CRITICAL
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It la
Dec 25, 20239.827NONO
CVE-2008-5110HIGH
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is pre
Nov 17, 20089.327NONO
CVE-2020-8019HIGH
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux E
Jun 29, 20207.826NONO
CVE-2022-38725HIGH
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandle
Jan 23, 20237.525NONO
CVE-2019-13498HIGH
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
Jul 29, 20197.425NONO
CVE-2019-13496HIGH
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML
Nov 4, 20198.124NONO
CVE-2023-51772HIGH
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It la
Dec 25, 20238.823NONO
CVE-2025-27582HIGH
The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within t
Jul 14, 20257.622NONO
CVE-2024-47619HIGH
syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to
May 7, 20257.522NONO
CVE-2002-1200HIGH
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are e
Oct 28, 20027.522NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
33%
60%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network8 (53.3%)
Unknown4 (26.7%)
Physical2 (13.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (60.0%)
High2 (13.3%)
Unknown4 (26.7%)
User Interaction
None10 (66.7%)
Unknown4 (26.7%)
Required1 (6.7%)
Privileges Required
Low2 (13.3%)
High0 (0.0%)
None9 (60.0%)
Unknown4 (26.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oneidentity.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oneidentity — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oneidentity's Products

View all 5 CNAs →

Top CWEs