Amazon Linux 2022 : (ALAS2022-2022-088)

It is, therefore, affected by a vulnerability as referenced in the ALAS2022-2022-088 advisory. - containerd is an open source container runtime. A bug was found in the containerd's CRI implementatio ...

Continue Reading
IBM Spectrum Protect: Multiple Vulnerabilities

### Background TSM provides the client and the API for IBM Spectrum Protect (formerly known as Tivoli Storage Manager), a backup and archival client/server solution targetting large tape libraries. ## ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

FortiWeb: FortiWeb – OS command injection due to direct input interpolation in API controllers (FG-IR-21-180)

The version of FortiWeb installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the FG-IR-21-180 advisory. - An improper neutralizatio ...

Continue Reading
Amazon Linux 2022 : (ALAS2022-2022-044)

It is, therefore, affected by a vulnerability as referenced in the ALAS2022-2022-044 advisory. - The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomca ...

Continue Reading
Security Bulletin: IBM Planning Analytics Workspace is affected by multiple vulnerabilities (CVE-2022-22968, CVE-2022-24785, CVE-2017-18214, CVE-2016-4055, CVE-2018-1000613, CVE-2020-15522, CVE-2018-1000180, CVE-2020-26939, CVE-2022-22314)

## Summary IBM Planning Analytics Workspace is affected by multiple vulnerabilities. Spring is used in IBM Planning Analytics Workspace in Server-Side Rest APIs as an indirect dependency by MongoDB th ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2022-36058

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
DotCMS 3.x < 5.3.8.10 / 21.x < 21.06.7 / 22.x < 22.03 Remote Code Execution

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows direc ...

Continue Reading
CVE-2022-26461

In vow, there is a possible undefined behavior due to an API misuse. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi ...

Continue Reading

Back to Main

Subscribe for the latest news: