Security Bulletin: A security vulnerabilities has been identified in IBM WebSphere Application Server Liberty shipped with IBM Business Automation Workflow (CVE-2023-28867)

## Summary WebSphere Application Server Liberty is shipped as part of IBM Business Automation Workflow containers and as part of the optional components Process Federation Server (since 8.5.6), and Us ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: IBM Watson Assistant for IBM Cloud Pak for Data is vulnerable to Envoy security bypass ( CVE-2023-27488)

## Summary Potential Enyoy security bypass vulnerability ( CVE-2022-25881) has been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data. Refer to details for additional informat ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Moderate: ruby:2.7 security, bug fix, and enhancement update

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. The following packages have been upgraded to a la ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Quest NetVault Backup Server < 11.4.5 – Process Manager Service SQL Injection / Remote Code Execution

Post ContentRead More ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

GitHub: Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to User’s Projects in Project V2 GraphQL api

An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app i ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Nextcloud: Mail app stores cleartext password in database until OAUTH2 setup is done

## Summary: The Mail app usually stores the user password encrypted. For XOAUTH2 the encrypted access token is stored in the same columns. However, during the time of the setup, XOAUTH2 accounts have ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

SoapUI 4.6.3 – Remote Code Execution

SoapUI 4.6.3 - Remote Code ExecutionRead More ...

Continue Reading

CVSS2 - HIGH

CVE-2014-1202

The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.Read More ...

Continue Reading

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: