Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM WebSphere Hybrid Edition, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867)

## Summary IBM WebSphere Application Server Liberty, which is bundled with IBM WebSphere Hybrid Edition, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867) ## Vulnerability Deta ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867)

## Summary IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is vulnerable to a denial of service due to GraphQL Java (CVE-2023-28867) ## Vulnerability De ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

(RHSA-2023:3559) Important: c-ares security update

The c-ares C library defines asynchronous DNS (Domain Name System) requests and provides name resolving API. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) For more ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-2478

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Asylum Ambuscade: A Cybercrime Group with Espionage Ambitions

[![Cybercrime Group](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() The threat actor known as **Asylum Ambuscade** has been obse ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Cross-site Scripting (XSS)

com.liferay.oauth2.provider.service is vulnerable to Cross-site Scripting (XSS). The vulnerability exists in the OAuth 2.0 module's `OAuth2ProviderApplicationRedirect` class in the library, which allo ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Important: xmlrpc

**Issue Overview:** An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server c ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Security Bulletin: There is a vulnerability in GraphQL used by IBM Maximo Asset Management (CVE-2022-37734)

## Summary There is a vulnerability in GraphQL used by IBM Maximo Asset Management. ## Vulnerability Details **CVEID: **[CVE-2022-37734]() **DESCRIPTION: **GraphQL Java is vulnerable to a denial of se ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: