Tanium Patch
cpe:2.3:a:tanium:tanium:*:*:*:*:*:*:*
- < 2.7.98
- < 2.24.159
- < 4.10.118
- < 1.0.224
- < 3.17.2300
- < 1.17.134
- < 2.9.188
- < 2.29.124
- < 1.2.33
- < 3.19.232
- < 2.12.82
- < 2.32.155
- < 1.3.40
- < 3.24.137
- < 1.22.288
An incorrect default permissions vulnerability has been identified in Tanium Patch, prior to Update 6 (v3.24.137). This vulnerability allows an authenticated Tanium user with specific service account permissions to read and write all platform content. The affected permissions include Partner Integration Service Account, Patch Service Account, Benchmark Service Account, Performance Components Manage, Discover Components Manage, and Comply Components Manage.
Exploitation of this vulnerability could enable an authenticated user with the specified permissions to access and modify all platform content, potentially leading to unauthorized changes or data exposure.
Users can update to Tanium Patch version 3.24.137 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.