CVE-2022-45378

** UNSUPPORTED WHEN ASSIGNED ** In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the cl ...

Continue Reading
php:8.0 security, bug fix, and enhancement update

libzip [1.7.3-1] - update to 1.7.3 php-pecl-apcu [5.1.20-1] - update to 5.1.20 php-pecl-rrd [2.0.3-1] - update to 2.0.3 php-pecl-xdebug3 [3.1.2-1] - update to 3.1.2 rhbz#2030322Read More ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

(RHSA-2022:8197) Moderate: php security, bug fix, and enhancement update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. The following packages have been upgraded to a later upstream version: php (8.0.20). (BZ#2095752) Security Fix(es) ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Abode Systems, Inc. iota All-In-One Security Kit UPnP logging format string injection vulnerabilities

# Talos Vulnerability Report ### TALOS-2022-1583 ## Abode Systems, Inc. iota All-In-One Security Kit UPnP logging format string injection vulnerabilities ##### October 20, 2022 ##### CVE Number CVE-20 ...

Continue Reading
SUSE SLES15 Security Update : php8 (SUSE-SU-2022:3661-1)

The remote SUSE Linux SLES15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:3661-1 advisory. - In PHP versions 7.3.x up to and including ...

Continue Reading
Gain Control of Rapidly Securing Your Critical APIs Without Worrying About Your Backend Stack

Imagine trying to protect your web application farm, while needing to integrate with all the different web servers' backend stacks on a one-to-one basis. This requires a WAF that understands systems s ...

Continue Reading
Moderate: php:7.4 security update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocke ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

8 KB is not enough: why WAFs can’t protect APIs

WAFs were a top-notch security instrument a decade ago, but now they are not. They fail to protect APIs. Meanwhile, the number of API-specific vulnerabilities grew more than twofold in 2022. According ...

Continue Reading

Back to Main

Subscribe for the latest news: