New Alerts for Dropbox Sign (Exploit), Cisco, SonicWall, Tinyproxy, IBM, and HashiCorp.
Dropbox Exploit
Dropbox has reported an incident in their Dropbox Sign product that exposed customer information as well as customers simply signing a document.
More info.
Multiple vulnerabilities in Cisco IP Phone firmware could allow a remote attacker to cause a DoS, gain unauthorized access, or view sensitive information on an affected system. CVSSv3 score of 7.5
More info.
SonicWall GMS contains security vulnerabilities, including use of a hardcoded password. Highest CVSSv3 score of 7.5
More info.
Tinyproxy contains security vulnerabilities that allows a remote atacker to achieve RCE. Highest CVSSv3 score of 9.8
No vendor response.
More info. And here. And here.
Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation. Highest CVSSv3 score of 9.8
More info.
IBM Controller has addressed multiple vulnerabilities. Highest CVSSv3 score of 9.8
More info.
IBM QRadar SIEM on Azure Cloud deployed from Azure Marketplace is vulnerable to a remote code execution issue found within the Microsoft Open Management Infrastructure (OMI). CVSSv3 score of 9.8
More info.
Vault Enterprise leaks sensitive HTTP request headers in audit log when deployed with a Performance Standby node.
More info.