Security Bulletin: Rational Test Control Panel component in Rational Test Virtualization Server and Rational Test Workbench is vulnerable to a denial of service attack in Spring Framework (CVE-2022-22971)

## Summary Spring Framework is vulnerable to a security issue affecting Rational Test Control Panel ## Vulnerability Details ** CVEID: **[CVE-2022-22971]() ** DESCRIPTION: **Vmware Tanzu Spring Framew ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Exploit for CVE-2022-39841

# CVE-2022-39841 Medusa's leaky WebSocket For more information ...Read More ...

Continue Reading
RHEL 8 : Red Hat JBoss Enterprise Application Platform 7.3.9 security update on RHEL 8 (Important) (RHSA-2021:3468)

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2021:3468 advisory. - jakarta-el: ELParserTokenManager enable ...

Continue Reading
RHEL 7 : Red Hat JBoss Enterprise Application Platform 7.3.9 security update on RHEL 7 (Important) (RHSA-2021:3467)

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2021:3467 advisory. - jakarta-el: ELParserTokenManager enable ...

Continue Reading
RHEL 6 : Red Hat JBoss Enterprise Application Platform 7.3.9 security update on RHEL 6 (Important) (RHSA-2021:3466)

The remote Redhat Enterprise Linux 6 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2021:3466 advisory. - jakarta-el: ELParserTokenManager enable ...

Continue Reading
Security Bulletin: IBM Sterling Control Center is vulnerable to denial of service by authenticated user due to Spring Framework (CVE-2022-22971)

## Summary Spring Framework is vulnerable to a denial of service, caused by a flaw with a STOMP over WebSocket endpoint. By sending a specially-crafted request, a remote authenticated attacker could e ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2022-37797

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the ser ...

Continue Reading
CVE-2022-37797

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the ser ...

Continue Reading

Back to Main

Subscribe for the latest news: