πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-22985 β€Ό

On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack against the APM. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22974 β€Ό

On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is due to an incomplete fix for CVE-2017-6167. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22975 β€Ό

On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, and 14.1.x before 14.1.3.1, under some circumstances, Traffic Management Microkernel (TMM) may restart on the BIG-IP system while passing large bursts of traffic. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22982 β€Ό

On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20406 (security_verify_information_queue) β€Ό

IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 198184.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20410 (security_verify_information_queue) β€Ό

IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20411 (security_verify_information_queue) β€Ό

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20409 (security_verify_information_queue) β€Ό

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 198188.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22980 β€Ό

In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory. User interaction is required to exploit this vulnerability in that the victim must run this utility on the Windows system. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22981 β€Ό

On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20408 (security_verify_information_queue) β€Ό

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20407 (security_verify_information_queue) β€Ό

IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 198185.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22973 β€Ό

On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x versions, JSON parser function does not protect against out-of-bounds memory accesses or writes. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22983 β€Ό

On BIG-IP AFM version 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5, authenticated users accessing the Configuration utility for AFM are vulnerable to a cross-site scripting attack if they attempt to access a maliciously-crafted URL. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
❌ Yandex Data Breach Exposes 4K+ Email Accounts ❌

In a security notice, Yandex said an employee had been providing unauthorized access to users’ email accounts β€œfor personal gain.”

πŸ“– Read

via "Threat Post".
❌ mHealth Apps Expose Millions to Cyberattacks ❌

Researcher testing of 30 mobile health apps for clinicians found that all of them had vulnerable APIs.

πŸ“– Read

via "Threat Post".
🦿 US Court system demands massive changes to court documents after SolarWinds hack 🦿

Multiple senators have demanded a hearing on what court officials know about the hackers' access to sensitive filings. The effects could make accessing documents harder for lawyers.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-22977 β€Ό

On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious server may cause TMM to restart and generate a core file. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22984 β€Ό

On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafted URI, a BIG-IP Advanced WAF or ASM virtual server configured with a DoS profile with Proactive Bot Defense (versions prior to 14.1.0), or a Bot Defense profile (versions 14.1.0 and later), may subject clients and web servers to Open Redirection attacks. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13949 β€Ό

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22504 β€Ό

Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server.

πŸ“– Read

via "National Vulnerability Database".