Microsoft
Microsoft System Center Operations Manager: vulnerabilidades y CVE
Microsoft System Center Operations Manager tiene 17 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses1
Críticas2
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-38649 | Alta (7.8) | 2.9% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2021-38645 | Alta (7.8) | 2.7% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2021-38647 | Crítica (9.8) | 100% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2021-38648 | Alta (7.8) | 11% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure Elevation of Privilege Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20967 | Alta (8.8) | 1.1% | — | 10 mar 2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-27743 | Alta (7.8) | 0.88% | — | 8 abr 2025 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. |
| CVE-2024-21334 | Crítica (9.8) | 20% | — | 12 mar 2024 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2024-21330 | Alta (7.8) | 0.99% | — | 12 mar 2024 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability |
| CVE-2023-36043 | Media (6.5) | 1.4% | — | 14 nov 2023 | Open Management Infrastructure Information Disclosure Vulnerability |
| CVE-2022-33640 | Alta (7.8) | 0.60% | — | 9 ago 2022 | System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability |
| CVE-2022-29149 | Alta (7.8) | 0.92% | — | 15 jun 2022 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability |
| CVE-2021-41352 | Alta (7.5) | 2.9% | — | 13 oct 2021 | SCOM Information Disclosure Vulnerability |
| CVE-2021-38649 | Alta (7.8) | 2.9% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2021-38648 | Alta (7.8) | 11% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2021-38647 | Crítica (9.8) | 100% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2021-38645 | Alta (7.8) | 2.7% | ⚠ Explotación activa | 15 sept 2021 | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2021-1728 | Alta (8.8) | 2.0% | — | 25 feb 2021 | System Center Operations Manager Elevation of Privilege Vulnerability |
| CVE-2020-1331 | Media (5.4) | 1.3% | — | 9 jun 2020 | A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing… |
| CVE-2015-2420 | Media (4.3) | 8.8% | — | 15 ago 2015 | Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbitrary web script or… |
| CVE-2013-0010 | Media (4.3) | 17% | — | 9 ene 2013 | Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations… |
| CVE-2013-0009 | Media (4.3) | 14% | — | 9 ene 2013 | Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.