Skip to main content

CND News and Blog

New Vulnerabilities Thursday 21 July


New Alerts for Cisco, Atlassian, Apple, IBM, Dell, and Linux.

Cisco 

Cisco has published 7 new bulletins, 1 rated Critical, 1 rated High, 4 rated Medium, and 1 Informational.
More info.

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. CVSSv3 score of 9.8
More info.

A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. CVSSv3 score of 7.4
More info.

Atlassian 

When the Questions for Confluence app is enabled on Confluence Server or Data Center, it creates a Confluence user account with the username disabledsystemuser, a hardcoded password, and is added to the confluence-users group. A remote attacker with knowledge of the hardcoded password could exploit this to log into Confluence. Atlassian rates this Critical.
More info.

A vulnerability in multiple Atlassian products allows a remote attacker to bypass Servlet Filters used by first and third party apps. Atlassian rates this Critical.
More info.

Apple 

Apple has released security updates for Safari, watchOS, macOS, tvOS, iOS, and iPadOS.
More info. And here.

IBM 

IBM Security Verify Information Queue (ISIQ) uses vulnerable Node.js, Wire Schema, and Google gRPC framework versions. Highest CVSSv3 score of 9.8
More info. And here. And here.

IBM PureData System for Operational Analytics contains a vulnerable version of IBM DB2. Highest CVSSv3 score of 9.8
More info.

Dell 

Dell VNX2 Operating Environment for File contains remediation for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system. Highest CVSSv3 score of 9.8
More info.

Linux 

SUSE has updated the kernel. More info.
Ubuntu has updated the kernel. More info.
Mageia has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Wednesday, 24 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/