Security Bulletin: IBM OpenPages Is Vulnerable to Security Checks bypass (CVE-2023-40683)

Summary A vulnerability caused by insufficient authorization checks of API requests by an authorized user is addressed. Vulnerability Details ** CVEID: CVE-2023-40683 DESCRIPTION: **IBM OpenPages cou ...

Continue Reading
Security Bulletin: IBM OpenPages Is Vulnerable to Security Checks bypass (CVE-2023-40683)

Summary A vulnerability caused by insufficient authorization checks of API requests by an authorized user is addressed. Vulnerability Details ** CVEID: CVE-2023-40683 DESCRIPTION: **IBM OpenPages cou ...

Continue Reading
Apache Solr allows read access to host environmet variables

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Us ...

Continue Reading
CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential

Summary The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing ...

Continue Reading
SMTP end-of-data uncertainty can be abused to spoof emails and bypass policies

Overview A vulnerability has been found in the way that SMTP servers and software handle the end-of-data sequences (essentially the end of a single email message) in mail messages. An attacker can use ...

Continue Reading
GPU kernel implementations susceptible to memory leak

Overview General-purpose graphics processing unit (GPGPU) platforms from AMD, Apple, and Qualcomm fail to adequately isolate process memory, thereby enabling a local attacker to read memory from other ...

Continue Reading
CVE-2022-1609

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker ...

Continue Reading
CVE-2023-50290

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Us ...

Continue Reading

Back to Main

Subscribe for the latest news: