Rocket.Chat Information Disclosure Vulnerability (CNVD-2022-69164)

Rocket.Chat is a set of open source team chat software. Rocket.Chat suffers from an information disclosure vulnerability that stems from the presence of an explicit transmission of sensitive informati ...

Continue Reading

CVSS3 - MEDIUM

Description of the security update for SharePoint Server 2019: October 11, 2022 (KB5002278)

None ## Summary This security update resolves a Microsoft SharePoint Server remote code execution vulnerability. To learn more about the vulnerability, see the following security advisories: * [Mic ...

Continue Reading

CVSS3 - HIGH

Description of the security update for SharePoint Server Subscription Edition: October 11, 2022 (KB5002290)

None ## Summary This security update resolves a Microsoft SharePoint Server remote code execution vulnerability. To learn more about the vulnerability, see the following security advisories: * [Mic ...

Continue Reading

CVSS3 - HIGH

Security Bulletin: WebSphere Application Server Liberty is vulnerable to Cross-site Scripting that affects Liberty for Java for IBM Cloud (CVE-2020-4303, CVE-2020-4304)

## Summary There is a cross-site scripting vulnerability in the OAuth, OpenID Connect and SAML features. This has been addressed. ## Vulnerability Details ** CVEID: **[CVE-2020-4303]() ** DESCRIPTION: ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security Bulletin: Liberty for Java for IBM Cloud is vulnerable to a denial of service (CVE-2020-4590)

## Summary There is a denial of service vulnerablility in IBM WebSphere Application Server Liberty used in Liberty for Java for IBM Cloud. ## Vulnerability Details ** CVEID: **[CVE-2020-4590]() ** DES ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Exploit for Injection in Forgerock Openam

# CVE-2021-29156 done right This Proof of Concept is realized b...Read More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

FlyteAdmin’s Default OAuth Authorization Server secret must be rotated

### Impact Users who enable the default [Flyte’s authorization server](https://docs.flyte.org/en/latest/deployment/cluster_config/auth_setup.html#oauth2-authorization-server) without changing the def ...

Continue Reading
CVE-2022-39222

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading

Back to Main

Subscribe for the latest news: