VendorsMicrosoftsystem_center_operations_managerall versions
Vulnerabilities

Microsoft System Center Operations Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2021-38647
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Published 2021-09-15 · Analyzed
9.8KEVEPSS 0.999
CVE-2024-21334
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Published 2024-03-12 · Analyzed
9.8EPSS 0.202
CVE-2021-1728
System Center Operations Manager Elevation of Privilege Vulnerability
Published 2021-02-25 · Modified
8.8EPSS 0.020
CVE-2026-20967
System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability
Published 2026-03-10 · Analyzed
8.8EPSS 0.011
CVE-2021-38648
Open Management Infrastructure Elevation of Privilege Vulnerability
Published 2021-09-15 · Analyzed
7.8KEVEPSS 0.114
CVE-2021-38649
Open Management Infrastructure Elevation of Privilege Vulnerability
Published 2021-09-15 · Analyzed
7.8KEVEPSS 0.029
CVE-2021-38645
Open Management Infrastructure Elevation of Privilege Vulnerability
Published 2021-09-15 · Analyzed
7.8KEVEPSS 0.027
CVE-2024-21330
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
Published 2024-03-12 · Analyzed
7.8EPSS 0.010
CVE-2022-29149
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
Published 2022-06-15 · Modified
7.8EPSS 0.009
CVE-2025-27743
Microsoft System Center Elevation of Privilege Vulnerability
Published 2025-04-08 · Analyzed
7.8EPSS 0.009
CVE-2022-33640
System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.8EPSS 0.006
CVE-2021-41352
SCOM Information Disclosure Vulnerability
Published 2021-10-13 · Modified
7.5EPSS 0.029
CVE-2023-36043
Open Management Infrastructure Information Disclosure Vulnerability
Published 2023-11-14 · Modified
6.5EPSS 0.014
CVE-2020-1331
A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'.
Published 2020-06-09 · Modified
5.4EPSS 0.013
CVE-2013-0010
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
Published 2013-01-09 · Modified
4.3EPSS 0.166
CVE-2013-0009
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
Published 2013-01-09 · Modified
4.3EPSS 0.136
CVE-2015-2420
Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "System Center Operations Manager Web Console XSS Vulnerability."
Published 2015-08-15 · Modified
4.3EPSS 0.088