By michele654 on Tuesday, 18 October 2022
Category: Vulnerabilities

New Vulnerabilities Tuesday 18 October


Oracle Quarterly Patches are due out today. New Alerts for NetApp, Apache Commons Text, IBM, and Linux.

Oracle 

Oracle Quarterly Patches are due out today. Pre-release document says there are 366 new security patches, 251 of which are remotely exploitable without authentication. Highest CVSSv3 score of 9.8
More info.

NetApp 

NetApp has published 3 new bulletins for vulnerabilities in their products. Highest CVSSv3 score of 10.
More info.

Multiple NetApp products incorporate NPM. NPM is susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or DoS. CVSSv3 score of 10. No patches.
More info.

Apache 

Apache Commons Text contains a vulnerability in default Lookup instances, which included interpolators that could result in arbitrary code execution or contact with remote servers. CVSSv3 score of 9.8
More info. And here.

IBM 

QRadar Pulse application add on to IBM QRadar SIEM is vulnerable to using components with known vulnerabilities. Highest CVSSv3 score of 9.8
More info.

Linux 

SUSE has updated the kernel. More info.
Red Hat has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments