PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Atlassian's Jira Service Management Found Vulnerable to Critical Vulnerability

vendredi 3 février 2023 à 08:55
Atlassian has released fixes to resolve a critical security flaw in Jira Service Management Server and Data Center that could be abused by an attacker to pass off as another user and gain unauthorized access to susceptible instances. The vulnerability is tracked as CVE-2023-22501 (CVSS score: 9.4) and has been described as a case of broken authentication with low attack complexity. "An

Atlassian's Jira Software Found Vulnerable to Critical Authentication Vulnerability

vendredi 3 février 2023 à 08:55

New High-Severity Vulnerabilities Discovered in Cisco IOx and F5 BIG-IP Products

vendredi 3 février 2023 à 08:26
F5 has warned of a high-severity flaw impacting BIG-IP appliances that could lead to denial-of-service (DoS) or arbitrary code execution. The issue is rooted in the iControl Simple Object Access Protocol (SOAP) interface and affects the following versions of BIG-IP - 13.1.5 14.1.4.6 - 14.1.5 15.1.5.1 - 15.1.8 16.1.2.2 - 16.1.3, and 17.0.0 "A format string vulnerability exists in iControl SOAP

New High-Severity Vulnerabilities Discovered in Cisco IOx and F5 BIG-IP Products

vendredi 3 février 2023 à 08:26

CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack

vendredi 3 février 2023 à 06:23
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on February 2 added two security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The first of the two vulnerabilities is CVE-2022-21587 (CVSS score: 9.8), a critical issue impacting versions 12.2.3 to 12.2.11 of the Oracle Web Applications Desktop Integrator product. "Oracle