βΌ CVE-2022-3147 βΌ
π Read
via "National Vulnerability Database".
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35725 βΌ
π Read
via "National Vulnerability Database".
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at WordPress.π Read
via "National Vulnerability Database".
β€1
β S3 Ep99: TikTok βattackβ β was there a data breach, or not? [Audio + Text] β
π Read
via "Naked Security".
Latest episode - listen now! (Or read if you prefer - full transcript inside.)π Read
via "Naked Security".
Naked Security
S3 Ep99: TikTok βattackβ β was there a data breach, or not? [Audio + Text]
Latest episode β listen now! (Or read if you prefer β full transcript inside.)
β How to deal with dates and times without any timezone tantrumsβ¦ β
π Read
via "Naked Security".
Heartfelt encouragement to embrace RFC 3339 - find out why!π Read
via "Naked Security".
Naked Security
How to deal with dates and times without any timezone tantrumsβ¦
Heartfelt encouragement to embrace RFC 3339 β find out why!
π’ UK, US condemn Iran for βunprecedentedβ cyber attack against Albania π’
π Read
via "ITPro".
The Balkan nation has cut ties with Iran following the hack, which took down national infrastructure and exposed government informationπ Read
via "ITPro".
IT PRO
UK, US condemn Iran for βunprecedentedβ cyber attack against Albania | IT PRO
The Balkan nation has cut ties with Iran following the hack, which took down national infrastructure and exposed government information
π’ DrayTek Vigor 2866ax review: Faster than you might expect π’
π Read
via "ITPro".
A versatile and very affordable SMB security router with Wi-Fi 6 and top-notch WAN redundancyπ Read
via "ITPro".
IT PRO
DrayTek Vigor 2866ax review: Faster than you might expect | IT PRO
A versatile and very affordable SMB security router with Wi-Fi 6 and top-notch WAN redundancy
π’ Thoma Bravo pulls plug on Darktrace takeover π’
π Read
via "ITPro".
Shares in the UK cyber firm slumped 30%, as investors had pinned hopes on takeover dealπ Read
via "ITPro".
IT PRO
Thoma Bravo pulls plug on Darktrace takeover | IT PRO
Shares in the UK cyber firm slumped 30%, as investors had pinned hopes on takeover deal
π’ HP patches high-severity security flaw in its own support tool π’
π Read
via "ITPro".
The application that's installed in every HP desktop and notebook was allowing hackers to elevate privileges through a DLL hijacking vulnerabilityπ Read
via "ITPro".
IT PRO
HP patches high-severity security flaw in its own support tool | IT PRO
The application that's installed in every HP desktop and notebook was allowing hackers to elevate privileges through a DLL hijacking vulnerability
βΌ CVE-2022-28742 βΌ
π Read
via "National Vulnerability Database".
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the applicationπ Read
via "National Vulnerability Database".
βΌ CVE-2022-28741 βΌ
π Read
via "National Vulnerability Database".
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.xπ Read
via "National Vulnerability Database".
βΌ CVE-2022-36617 βΌ
π Read
via "National Vulnerability Database".
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38614 βΌ
π Read
via "National Vulnerability Database".
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38613 βΌ
π Read
via "National Vulnerability Database".
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40317 βΌ
π Read
via "National Vulnerability Database".
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28740 βΌ
π Read
via "National Vulnerability Database".
aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38615 βΌ
π Read
via "National Vulnerability Database".
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39810 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34165 βΌ
π Read
via "National Vulnerability Database".
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39809 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocessor.jsp via the name parameter. Session hijacking or similar attacks would not be possible.π Read
via "National Vulnerability Database".
π΄ Business Security Starts With Identity π΄
π Read
via "Dark Reading".
How identity-centric security can support business objectives.π Read
via "Dark Reading".
Dark Reading
Business Security Starts With Identity
How identity-centric security can support business objectives.
βΌ CVE-2022-38639 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.π Read
via "National Vulnerability Database".