By michele654 on Thursday, 06 June 2024
Category: Vulnerabilities

New Vulnerabilities Thursday 06 June

New Alerts for Cisco, NetApp, Bitdefender, and Linux.

Cisco 

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow a remote attacker to perform a stored XSS attack by exploiting a RFI vulnerability or perform a SSRF attack. Highest CVSSv3 score of 7.2
More info.

NetApp 

NetApp has published 10 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
No patches yet.
More info.

Bitdefender 

GravityZone Console contains a host whitelist parser issue in the proxy service implemented in the GravityZone Update Server that allows a remote attacker to cause a server-side request forgery. CVSSv3 score of 8.1
Automatic updates have been published.
More info.

Linux 

Oracle Linux has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details