Security Bulletin: IBM QRadar Wincollect is vulnerable to using components with known vulnerabilities

Summary IBM QRadar Wincollect is vulnerable to using components with known vulnerabilities. IBM has addressed the relevant vulnerabilities in an update. Vulnerability Details ** CVEID: CVE-2024-6874 ...

Continue Reading
Exploit for Code Injection in Vmware Spring Cloud Data Flow

CVE-2024-37084-Poc Setup ,Analysis , Demo exploit and poc about CVE-2024-37084 How to use : ``` py .CVE-2024-37084-Poc.py -h usage: python poc_cve_2024_37084.py --target_url --version --origin --p ...

Continue Reading
Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score

Microsoft disclosed four vulnerabilities that are actively being exploited in the wild as part of its regular Patch Tuesday security update this week in what's become a regular occurrence for the ...

Continue Reading
XWiki Platform document history including authors of any page exposed to unauthorized actors

Impact The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the ...

Continue Reading
XWiki Platform document history including authors of any page exposed to unauthorized actors

Impact The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the ...

Continue Reading
Microsoft and Adobe Patch Tuesday, September 2024 Security Update Review

Microsoft's September Patch Tuesday updates are out, addressing a range of vulnerabilities across multiple products. Let's dive into the key updates and their implications. Microsoft Patch ...

Continue Reading
Session is cached for OpenID and OAuth2 if `redirect` is not used

Summary Unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. For example: - Project is config ...

Continue Reading
Session is cached for OpenID and OAuth2 if `redirect` is not used

Summary Unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. For example: - Project is config ...

Continue Reading

Back to Main

Subscribe for the latest news: