Tanium Performance
cpe:2.3:a:tanium:tanium:*:*:*:*:*:*:*
- < 2.7.98
- < 2.24.159
- < 4.10.118
- < 1.0.224
- < 3.17.2300
- < 1.17.134
- < 2.9.188
- < 2.29.124
- < 1.2.33
- < 3.19.232
- < 1.21.141
- < 2.12.82
- < 2.32.155
- < 1.3.40
- < 3.24.137
- < 1.22.288
An incorrect default permissions vulnerability has been identified in Tanium Performance, prior to Update 6 (v1.22.288). This vulnerability allows an authenticated Tanium user with specific service account permissions to read and write all platform content. The issue arises from improper default permission settings that could be exploited by users with certain roles.
Exploitation of this vulnerability could enable an authenticated user with the appropriate service account permissions to access and modify all platform content, potentially leading to unauthorized data manipulation or exposure.
Users can update to Tanium Performance version 1.22.288 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.