CVE-2019-17076

CRITICAL

Jamf < 9.101.4 - Insecure Deserialization

Title source: rule

Description

An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server.

Scores

CVSS v3 9.8
EPSS 0.0554
EPSS Percentile 90.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

jamf/jamf < 9.101.4

Timeline

Published Jan 08, 2020
Tracked Since Feb 18, 2026