Optus data breach “attacker” says sorry, it was a mistake

Since Australian telecoms company Optus disclosed a security breach on September 22, 2022, a lot has been happening. Much of it reads like a movie script. ## Prologue A hacker acting under the pseudon ...

Continue Reading
CVE-2022-36068

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and e ...

Continue Reading
CVE-2022-39266

isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, ...

Continue Reading
Security Bulletin: Multiple Security Vulnerabilities in IBM Sterling Control Center

## Abstract A number of security vulnerabilities have been discovered in the Java Runtime Environment and the Cognos Business Intelligence components included in IBM SCC. ## Content **CVE ID: **[_CVE ...

Continue Reading

CVSS2 - HIGH

Security Bulletin: Balanced Warehouse C3000, C4000, & D5100, IBM Smart Analytics System 1050, 2050, 5600, 5710, 7600, 7700, & 7710, and PureData System for Operational Analytics A1791 Java API Documentation Frame Injection Vulnerability (CVE-2013-1571)

## Abstract Java API Documentation contains a frame injection vulnerability. ## Content **VULNERABILITY DETAILS: ** **CV****EID: ****CVE-2013-1571** **DESCRIPTION:** HTML documentation generated ...

Continue Reading

CVSS2 - MEDIUM

Security Bulletin: IBM® Sterling B2B Integrator and IBM® Sterling File Gateway Java API Documentation Frame Injection Vulnerability (CVE-2013-1571)

## Abstract Java API Documentation contains a frame injection vulnerability. ## Content **VULNERABILITY DETAILS: ** **CVEID: **CVE-2013-1571 **DESCRIPTION: **HTML documentation generated by the J ...

Continue Reading

CVSS2 - MEDIUM

Security Bulletin: Some IBM Sterling Order Management APIs may return database sensitive information (CVE-2013-0578)

## Abstract Some IBM Sterling Order Management APIs may return database sensitive information when API tester is deployed in the environment. ## Content **VULNERABILITY DETAILS: ** **DESCRIPTION: * ...

Continue Reading

CVSS2 - LOW

Security Bulletin: IBM InfoSphere Master Data Management Java API Documentation Frame Injection Vulnerability (CVE-2013-1571)

## Abstract API Documentation contains a frame injection vulnerability ## Content **VULNERABILITY DETAILS: ** **CVEID: **CVE-2013-1571 **DESCRIPTION: **HTML documentation generated by the Javadoc ...

Continue Reading

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: