By michele654 on Thursday, 18 January 2024
Category: Vulnerabilities

New Vulnerabilities Thursday 18 January


New Alerts for Nextcloud, Microsoft Edge (Exploit), IBM, HPE, BD, and Linux.

Nextcloud 

Global Site Selector password verification method allows a remote attacker to authenticate as another user. CVSSv3 score of 9.6
More info.

Microsoft Exploit

Microsoft has updated Edge for the latest Chromium security updates. One has been exploited.
More info.

IBM 

There were multiple security vulnerabilities fixed in IBM Security Verify Access. Highest CVSSv3 score of 9.8
More info. And here.

The remote administration API in IBM App Connect Enterprise is vulnerable to an information disclosure and denial of service vulnerability due to improper Brute Force protection. CVSSv3 score of 9.1
More info.

Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation. Highest CVSSv3 score of 9.8
More info.

IBM App Connect Enterprise Toolkit & IBM Integration Bus Toolkit are vulnerable to a remote attacker due to Apache Derby. CVSSv3 score of 9.1
More info.

Multiple security vulnerabilities affect IBM Robotic Process Automation for Cloud Pak. Highest CVSSv3 score of 9.8
More info.

IBM Storage Ceph is vulnerable to Prototype Pollution in Ramda and improper authentication in Crewjam/SAML. Highest CVSSv3 score of 9.8
More info. And here.

HPE 

Several security vulnerabilities have been identified in Apache Web Server running on HP-UX. Highest CVSSv3 score of 9.8
More info.

BD 

BD has updated Care Coordination Engine and Identity Provider Manager to fix vulnerabilities in third-party software.
More info.

Linux 

SUSE has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments