Security Bulletin: Apache CXF vulnerability identified in IBM Tivoli Application Dependency Discovery Manager

## Summary This security bulletin addresses the vulnerabilities in Open Source Apache CXF that affect IBM Tivoli Application Dependency Discovery Manager (CVE-2022-46364,CVE-2022-46363). IBM Tivoli Ap ...

Continue Reading

CVSS3 - CRITICAL

CVE-2023-0296

The Birthday attack against 64-bit block ciphers (CVE-2016-2183) was reported for the health checks port (9979) on the etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the et ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: A vulnerability exists in the IBM® SDK, Java™ Technology Edition affecting IBM Tivoli Netcool Configuration Manager (CVE-2021-28167).

## Summary A vulnerability exists in IBM® SDK Java™ Technology Edition, Version 8, which is used by IBM Tivoli Netcool Configuration Manager IP Edition v6.4.2. ## Vulnerability Details ** CVEI ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security Bulletin: An issue was identified with IBM® Runtime Environment Java™ Technology Edition, Version 8 supplied by IBM MQ (CVE-2021-2163)

## Summary An issue was identified with IBM® Runtime Environment Java™ Technology Edition, Versions 7 and 8 supplied by IBM MQ versions. The IBM® Runtime Environment Java™ Technolog ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

Security Bulletin: An issue was identified in IBM WebSphere Application Server Liberty that IBM MQ ships (CVE-2022-34165)

## Summary An issue was identified in IBM WebSphere Application Server Liberty that IBM MQ ships to provide MQ Console and MQ REST API functionality. ## Vulnerability Details **CVEID: **[CVE-2022-3416 ...

Continue Reading

CVSS3 - MEDIUM

Gravitee API Management contains Path Traversal

**This CVE addresses the partial fix for CVE-2019-25075** Gravitee API Management before 3.15.13 allows path traversal through HTML injection. A certain HTML injection combined with path traversal in ...

Continue Reading

CVSS3 - MEDIUM

Security Bulletin: Vulnerabilities in FasterXML affects IBM Common Licensing’s Administration And Reporting Tool (ART) and its Agent (217968, CVE-2020-36518)

## Summary Security Vulnerablities have been addressed in IBM Common Licensing. Faster-XML Jackson is a JSON to Java object conversion API (217968, CVE-2020-36518). A fix is available to address the v ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Improper Authentication

github.com/usememos/memos is vulnerable to improper authentication. The vulnerability allows a remote attacker to use the `Reset` API on any user without consent via IDOR.Read More ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: