CVE-2019-17076

CRITICAL

Jamf Pro 9.4-9.101.4 and 10.x < 10.15.1 - Remote Code Execution via JSON Deserialization

Title source: llm
STIX 2.1

Description

An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0250
EPSS Percentile 82.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (1)
jamf/jamf 9.4 - 9.101.4
Published Jan 08, 2020
Tracked Since Feb 18, 2026