By michele654 on Monday, 20 January 2025
Category: Vulnerabilities

New Vulnerabilities Monday 20 January


New Alerts for Google ChromeOS, Microsoft Edge, HPE, F5, NetApp, and Linux. Oracle Quarterly Patches and Node.js patches will be published tomorrow.

Oracle Quarterly Patch pre-release announcement here.
Node.js pre-release announcement here.​

Google 

Google has updated ChromeOS to fix vulnerabilities in the included Chrome browser.
More info.

Microsoft 

Microsoft has updated Edge to include the latest chromium fixes.
More info.

HPE 

A security vulnerability has been fixed in Telco Service Orchestrator software that a remote attacker could exploit for unauthorized data injection. CVSSv3 score of 5.3
More info.

F5 

Traffix SDC contains a vulnerability that allows a remote attacker to bypass authentication and gain unauthorized access to sensitive information or privilege escalation. CVSSv3 score of 9.8
No patches yet.
More info.

Traffix SDC contains a vulnerability in Apache Tomcat that allows a remote attacker to gain access to the information leaking from a previous request/response. CVSSv3 score of 5.3
No patches yet.
More info.

NetApp 

NetApp has published 10 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
No patches yet.
More info.

Linux 

SUSE has updated rsync. More info.
OpenSUSE has updated rsync. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details