Security Bulletin: IBM UrbanCode Release is vulnerable to a bypass of security restrictions due to use of Apache Tomcat (CVE-2022-25762).

## Summary Apache Tomcat is used by IBM UrbanCode Release. This fix includes Apache Tomcat 8.5.79. ## Vulnerability Details ** CVEID: **[CVE-2022-25762]() ** DESCRIPTION: **Apache Tomcat could allow a ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Security Bulletin: IBM UrbanCode Build is vulnerable to a bypass of security restrictions due to use of Apache Tomcat (CVE-2022-25762).

## Summary Apache Tomcat is used by IBM UrbanCode Build. This fix includes Apache Tomcat 8.5.79. ## Vulnerability Details ** CVEID: **[CVE-2022-25762]() ** DESCRIPTION: **Apache Tomcat could allow a r ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

CVE-2021-3690

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from thi ...

Continue Reading
GLSA-202208-34 : Apache Tomcat: Multiple Vulnerabilities

The remote host is affected by the vulnerability described in GLSA-202208-34 (Apache Tomcat: Multiple Vulnerabilities) - When responding to new h2c connection requests, Apache Tomcat versions 10.0.0 ...

Continue Reading
CVE-2021-3690

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from thi ...

Continue Reading
GO-2022-0947

In Mellium mellium.im/xmpp, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security Bulletin: Multiple Vulnerabilities in Node.js affect IBM Cloud Pak System

## Summary Multiple Vulnerabilities have been found in Node.js used by the Common UI in Cloud Pak System. Cloud Pak System has addressed these vulnerabilities. ## Vulnerability Details ** CVEID: **[CV ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Wallarm at Black Hat USA 2022

Black Hat USA is celebrating its 25th anniversary, and Wallarm will be on hand for the festivities. If you’re headed to Vegas this year, we invite you to meet our crew and talk about API security. ** ...

Continue Reading

Back to Main

Subscribe for the latest news: