Skip to main content

CND News and Blog

New Vulnerabilities Thursday 01 February


New Alerts for Baxter, Meinberg, Apple Vision Pro (Exploit), IBM, Dell, and NetApp.

Baxter 

Baxter has published a list of products distributed by Baxter that are vulnerable to the Mirth Connect RCE. CVSSv3 score of 9.8
Some patches are available, others are expected Q1 2024.
More info.

Meinberg 

Meinberg has updated LANTIME firmware to fix vulnerabilities in third-party software. Some of the vulnerabilities date to 2021.
More info.

Apple Exploit

Apple has updated Vision Pro to fix an actively exploited vulnerability.
More info.

IBM 

Multiple Tensorflow vulnerabilitiies have been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data. Highest CVSSv3 score of 9.8
More info.

Multiple vulnerabilities were addressed in IBM Cloud Pak for AIOps. Highest CVSSv3 score of 9.1
More info.

IBM Sterling Control Center is vulnerable to denial of service attack due to Apache Axis. CVSSv3 score of 9.8
More info.

IBM Security Guardium is affected by multiple vulnerabilities. Highest CVSSv3 score of 9.8
More info.

Vulnerabilities in Linux Kernel and Apache Axis can affect IBM Storage Protect Plus. Highest CVSSv3 score of 9.8
More info.

IBM Sterling Transformation Extender is vulnerable to multiple issues due to Keycloak, Swagger UI, IBM GSKit, and Apache ActiveMQ. Highest CVSSv3 score of 9.8
More info.

IBM Watson Discovery Cartridge for IBM Cloud Pak for Data affected by vulnerability in Apache Derby. CVSSv3 score of 9.1
More info.

User Behavior Analytics application add on to IBM QRadar SIEM is vulnerable to using components with known vulnerabilities. Highest CVSSv3 score of 9.1
More info.

Oracle Outside In Technology has Security vulnerabilities which may be exposed within the use of Content Manager Enterprise Edition. Highest CVSSv3 score of 10.
More info.

IBM Data Risk Manager is affected by multiple vulnerabilities. Highest CVSSv3 score of 9.8
More info.

IBM Instana Observability is affected by Vulnerabilities in Golang GO and VMware Tanzu Spring Framework. Highest CVSSv3 score of 9.8
More info.

Dell 

EMC VPlex has been updated to fix multiple third-party component vulnerabilities. Dell rates this Critical.
More info.

vRealize Data Protection Extension has been updated to fix the VMware Aria Automation vulnerability. CVSSv3 score of 9.9
More info.

Dell Data Protection Search has been updated to fix multiple security vulnerabilities. Dell rates this Critical.
More info.

NetApp 

NetApp has published 9 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
No patches yet.
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/