By michele654 on Friday, 13 December 2024
Category: Vulnerabilities

New Vulnerabilities Friday 13 December


New Alerts for Cleo (Exploit), Microsoft, Dell, HPE, Progress, IBM, and Linux.

Cleo Exploit

An unrestricted file upload and download vulnerability could lead to RCE in Harmony, VLTrader, and LexiCom. This is actively exploited.
More info. And here. And here. And here.

Microsoft 

Deserialization of untrusted data in Microsoft Update Catalog allows a remote attacker to elevate privileges on the website's webserver. Highest CVSSv3 score of 9.3
More info.

Microsoft has updated Edge with the latest chromium fixes.
More info.

Dell 

Dell has published new Critical bulletins for PowerFlex Rack, PowerFlex Appliance, and APEX Cloud Platform products.
More info.

HPE 

Aruba Networking AirWave Management has been updated for multiple vulnerabilities. Highest CVSSv3 score of 7.2
More info.

Telco Service Orchestrator software contains vulnerabilities that allow a remote attackercross-site request forgery, elevation of privilege, and DoS. Highest CVSSv3 score of 8.1
More info.

Progress 

WhatsUp Gold has been updated to fix several vulnerabilities. Highest CVSSv3 score of 8.8
More info.

IBM 

IBM has published Critical bulletins for Process Mining, Operations Analytics, Watson Speech Services Cartridge, Guardium Data Security Center, App Connect Enterprise, CloudPak for AIOps, Cognos Dashboards, and QRadar SIEM.
More info.

Linux 

Ubuntu has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details