Home/Product/microsoft system center operations manager
Product

microsoft system center operations manager

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-20967
all versions
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
8.8HIGH
CVE-2025-27743
all versions
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
7.8HIGH
CVE-2024-21334
all versions
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
9.8CRITICAL
CVE-2024-21330
all versions
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
7.8HIGH
CVE-2023-36043
all versions
Open Management Infrastructure Information Disclosure Vulnerability
6.5MEDIUM
CVE-2022-33640
all versions
System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-29149
all versions
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-41352
all versions
SCOM Information Disclosure Vulnerability
7.5HIGH
CVE-2021-38649
all versions
Open Management Infrastructure Elevation of Privilege Vulnerability
7.0HIGH
CVE-2021-38648
all versions
Open Management Infrastructure Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-38647
all versions
Open Management Infrastructure Remote Code Execution Vulnerability
9.8CRITICAL
CVE-2021-38645
all versions
Open Management Infrastructure Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-1728
all versions
System Center Operations Manager Elevation of Privilege Vulnerability
8.8HIGH
CVE-2020-1331
all versions
A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web re
5.4MEDIUM
CVE-2015-2420
all versions
Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollu
CVE-2013-0010
all versions
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to
CVE-2013-0009
all versions
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to
threatengine.sh