βΌ CVE-2020-4700 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user belonging to a specific user group to create a user or group with administrative privileges. IBM X-Force ID: 187077.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4705 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187190.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4476 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181778.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4475 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.π Read
via "National Vulnerability Database".
βΌ CVE-2020-23489 βΌ
π Read
via "National Vulnerability Database".
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27991 βΌ
π Read
via "National Vulnerability Database".
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).π Read
via "National Vulnerability Database".
βΌ CVE-2020-28723 βΌ
π Read
via "National Vulnerability Database".
Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27989 βΌ
π Read
via "National Vulnerability Database".
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).π Read
via "National Vulnerability Database".
βΌ CVE-2020-4692 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitive information from the Dashboard UI. IBM X-Force ID: 186780.π Read
via "National Vulnerability Database".
βΌ CVE-2020-28692 βΌ
π Read
via "National Vulnerability Database".
In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4566 βΌ
π Read
via "National Vulnerability Database".
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially highly sensitive information in log files that could be read by an authenticated user. IBM X-Force ID: 184083.π Read
via "National Vulnerability Database".
π¦Ώ Cybersecurity: Top hackers make big money from bug bounties π¦Ώ
π Read
via "Tech Republic".
You might not make a million dollars, but hackers are making good money from reporting vulnerabilities.π Read
via "Tech Republic".
TechRepublic
Meet the hackers who earn millions for saving the web. How bug bounties are changing everything about security
These hackers are finding security bugs--and getting paid for it. That's changing the dynamics of cybersecurity.
β Citrix SD-WAN Bugs Allow Remote Code Execution β
π Read
via "Threat Post".
The bugs tracked as CVE-2020β8271, CVE-2020β8272 and CVE-2020β8273 exist in the Citrix SD-WAN Center.π Read
via "Threat Post".
Threat Post
Citrix SD-WAN Bugs Allow Remote Code Execution
The bugs tracked as CVE-2020β8271, CVE-2020β8272 and CVE-2020β8273 exist in the Citrix SD-WAN Center.
π¦Ώ Data is worth its weight in gold π¦Ώ
π Read
via "Tech Republic".
IT leaders are placing an increased, permanent focus on the value of data, digital transformation, and security, a new survey finds.π Read
via "Tech Republic".
TechRepublic
Data is worth its weight in gold
IT leaders are placing an increased, permanent focus on the value of data, digital transformation, and security, a new survey finds.
π Amendments to Singapore's Personal Data Protection Act Take Effect π
π Read
via "Digital Guardian".
Singapore's recently amended Personal Data Protection Act (PDPA) increases the penalizations imposed on companies for data breaches and recognizes the rights of individuals to protect their personal data.π Read
via "Digital Guardian".
Digital Guardian
Amendments to Singapore's Personal Data Protection Act Take Effect
Singapore's recently amended Personal Data Protection Act (PDPA) increases the penalizations imposed on companies for data breaches and recognizes the rights of individuals to protect their personal data.
π΄ Twitter Taps Mudge π΄
π Read
via "Dark Reading".
Noted security researcher Peiter Zatko joins the social network as head of security.π Read
via "Dark Reading".
Dark Reading
Twitter Taps Mudge
Noted security researcher Peiter Zatko joins the social network as head of security.
βΌ CVE-2020-5424 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2020-26510 βΌ
π Read
via "National Vulnerability Database".
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2020-26508 βΌ
π Read
via "National Vulnerability Database".
The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.π Read
via "National Vulnerability Database".
βΌ CVE-2020-26509 βΌ
π Read
via "National Vulnerability Database".
Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.π Read
via "National Vulnerability Database".
β Attackers Target Porn Site Goers in βMalsmokeβ Zloader Attack β
π Read
via "Threat Post".
A fake Java update found on various porn sites actually downloads the well-known Zloader malware.π Read
via "Threat Post".
Threat Post
Attackers Target Porn Site Goers in βMalsmokeβ Zloader Attack
A fake Java update found on various porn sites actually downloads the well-known Zloader malware.