Security Bulletin: IBM Planning Analytics Workspace is affected by vulnerabilties

## Summary IBM Planning Analytics Workspace is affected by vulnerabilities. Node.js is an open-source and cross-platform JavaScript runtime environment (CVE-2022-35255, CVE-2022-35256). Node-tar is a ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Bypassing OGNL sandboxes for fun and charities

## Overview[]() Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. In the ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Fedora 37 : mediawiki (2023-30a7a812f0)

The remote Fedora 37 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2023-30a7a812f0 advisory. - An issue was discovered in MediaWiki before 1.3 ...

Continue Reading

CVSS3 - MEDIUM

Rocky Linux 9 : php (RLSA-2022:8197)

The remote Rocky Linux 9 host has packages installed that are affected by a vulnerability as referenced in the RLSA-2022:8197 advisory. Note that Nessus has not tested for this issue but has instead r ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

November 8, 2022—KB5020009 (Monthly Rollup)

None ## **Summary** Learn more about this cumulative security update, including improvements, any known issues, and how to get the update. **REMINDER** [Windows Server 2012]() has reached the end of m ...

Continue Reading

CVSS3 - HIGH

November 8, 2022—KB5020023 (Monthly Rollup)

None ## **Summary** Learn more about this cumulative security update, including improvements, any known issues, and how to get the update. **REMINDER** [Windows 8.1]() will reach end of support on Jan ...

Continue Reading

CVSS3 - HIGH

Secure Web Gateway 10.2.11 Cross Site Scripting Vulnerability

Secure Web Gateway version 10.2.11 suffers from a cross site scripting vulnerability. RedTeam Pentesting identified a vulnerability which allows attackers to craft URLs to any third-party website that ...

Continue Reading

CVSS3 - MEDIUM

Authentication Bypass

flarum is vulnerable to Authentication Bypass. The vulnerability exists because the library does not properly check access for post creation when the first post is deleted, allowing an attacker who ca ...

Continue Reading

CVSS3 - LOW

Back to Main

Subscribe for the latest news: