apparoformation.fr Cross Site Scripting vulnerability OBB-2920501

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
Security Bulletin: Spoofing vulnerability in IBM Business Automation Workflow (CVE-2019-4045)

## Summary A Spoofing vulnerability has been found in IBM Business Automation Workflow. ## Vulnerability Details **CVEID:** [CVE-2019-4045]() **DESCRIPTION:** IBM Business Automation Workflow and IBM ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security Bulletin: Blind SQL injection vulnerability in IBM Business Automation Workflow and IBM Business Process Manager (CVE-2018-1674)

## Summary IBM Business Process Manager and IBM Business Automation Workflow are vulnerable to blind SQL injection due to insufficient validation of user-provided input in an API. ## Vulnerability Det ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

EulerOS 2.0 SP9 : python-jwt (EulerOS-SA-2022-2302)

According to the versions of the python-jwt package installed, the EulerOS installation on the remote host is affected by the following vulnerabilities : - PyJWT is a Python implementation of RFC 75 ...

Continue Reading
Security Bulletin: A vulnerability has been identified in IBM WebSphere Application Server shipped with IBM Digital Business Automation Workflow family products (CVE-2018-1794)

## Summary WebSphere Application Server is shipped as a component of IBM Business Automation Workflow, IBM Business Process Manager, and IBM Business Process Manager Enterprise Service Bus. Informatio ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2022-37661

SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.Read More ...

Continue Reading
CVE-2022-22520

A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in al ...

Continue Reading

CVSS3 - HIGH

CVE-2022-38796

A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: