The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality an ...
Continue ReadingFebruary 27, 2023
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromi ...
Continue ReadingFebruary 27, 2023
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead ...
Continue ReadingFebruary 27, 2023
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated ...
Continue ReadingFebruary 27, 2023
Updates of ['telegraf', 'linux-secure', 'harfbuzz', 'kafka', 'bindutils', 'openssl', 'linux-rt', 'python3', 'gnutls', 'containerd', 'linux', 'linux-esx', 'linux-aws'] packages of Photon OS have been r ...
Continue ReadingFebruary 27, 2023
The remote SUSE Linux SLED15 / SLES15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0513-1 advisory. - Password_verify() a ...
Continue ReadingFebruary 25, 2023
The remote SUSE Linux SLES15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0514-1 advisory. - Password_verify() always ret ...
Continue ReadingFebruary 25, 2023
The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0515-1 advisory. - Password_verify() always return true with ...
Continue ReadingFebruary 25, 2023
Back to Main