Security Bulletin: IBM MQ Console is affected by a security bypass vulnerablity (CVE-2024-40681)

Summary IBM MQ has addressed a security bypass vulnerability in the IBM MQ Console. Vulnerability Details CVEID: CVE-2024-40681 DESCRIPTION: IBM MQ could allow an authenticated user in a specifically ...

Continue Reading
CVE-2024-45392 SuiteCRM has wrong deletion permission checks on API delete call

SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Vers ...

Continue Reading
Debian dla-3873 : nova-api – security update

The remote Debian 11 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-3873 advisory. - --------------------------------------------------------------- ...

Continue Reading
Debian dla-3872 : glance – security update

The remote Debian 11 host has packages installed that are affected by a vulnerability as referenced in the dla-3872 advisory. - ------------------------------------------------------------------------ ...

Continue Reading
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 26, 2024 to September 1, 2024)

Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 7th, 2024, XSS vulnerabilities in all plugins and themes with >=1,000 ...

Continue Reading
Debian dla-3871 : cinder-api – security update

The remote Debian 11 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-3871 advisory. - --------------------------------------------------------------- ...

Continue Reading
Amazon Linux 2 : docker (ALASECS-2024-041)

The version of docker installed on the remote host is prior to 25.0.3-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2ECS-2024-041 advisory. A malicious HTTP sender ...

Continue Reading
CVE-2024-45392 SuiteCRM has wrong deletion permission checks on API delete call

SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Vers ...

Continue Reading

Back to Main

Subscribe for the latest news: