VYPR

Ops Manager

by MongoDB

CVEs (4)

  • CVE-2020-7927HigNov 23, 2020
    risk 0.53cvss 8.1epss 0.01

    Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB Ops Manager v4.3 versions prior to and…

  • CVE-2026-8431HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.00

    An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.  This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions…

  • CVE-2021-20335MedFeb 11, 2021
    risk 0.44cvss 6.7epss 0.00

    For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager versions prior to and including 4.4.12 triggers a bug where Automation thinks SSL is being…

  • CVE-2019-2388MedMay 13, 2020
    risk 0.38cvss 5.8epss 0.01

    In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1…