Security Bulletin: Multiple vulnerabilities in IBM SDK for Node.js and packaged modules affect IBM Business Automation Workflow Configuration Editor

## Summary IBM Business Automation Workflow Configuration Editor is vulnerable to multiple attacks. ## Vulnerability Details ** CVEID: **[CVE-2022-24999]() ** DESCRIPTION: **Express.js Express is vuln ...

Continue Reading

CVSS3 - HIGH

AlmaLinux 9 : openssl (ALSA-2023:0946)

The remote AlmaLinux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the ALSA-2023:0946 advisory. - A read buffer overrun can be triggered in X.509 certi ...

Continue Reading

CVSS3 - HIGH

Oracle Linux 9 : openssl (ELSA-2023-0946)

The remote Oracle Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2023-0946 advisory. - A NULL pointer can be dereferenced when signatures ...

Continue Reading

CVSS3 - HIGH

Privilege Escalation

github.com/mosn/mosn is vulnerable to Privilege Escalation. The vulnerability exists due to the `prefixMatcher` function in `matcher.go` while using JWT authorization, which is case-sensitive to the p ...

Continue Reading

CVSS3 - CRITICAL

Ubuntu 18.04 LTS / 20.04 LTS / 22.04 LTS : PHP vulnerabilities (USN-5902-1)

The remote Ubuntu 18.04 LTS / 20.04 LTS / 22.04 LTS host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-5902-1 advisory. - In PHP 8.0.X before 8.0.28, ...

Continue Reading

CVSS3 - CRITICAL

Ubuntu 18.04 LTS / 20.04 LTS / 22.04 LTS : PHP vulnerabilities (USN-5902-1)

The remote Ubuntu 18.04 LTS / 20.04 LTS / 22.04 LTS host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-5902-1 advisory. - In PHP 8.0.X before 8.0.28, ...

Continue Reading

CVSS3 - CRITICAL

Security Bulletin: IBM WebSphere Application Server Liberty is vulnerable to a denial of service due to Google protobuf-java (CVE-2022-3171, CVE-2022-3509)

## Summary There is a vulnerability in the Google protobuf-java library used by IBM WebSphere Application Server Liberty with the grpc-1.0 or grpcClient-1.0 feature enabled. This has been addressed. # ...

Continue Reading

CVSS3 - HIGH

php security update

[8.0.27-1] - rebase to 8.0.27Read More ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: