Security
Headlines
HeadlinesLatestCVEs

Tag

#oracle

Oracle patches ‘miracle exploit’ impacting Middleware Fusion, cloud services

Researchers describe discovery of ‘mega’ zero-day

PortSwigger
#vulnerability#web#microsoft#js#oracle#rce#auth#zero_day#sap
CVE-2021-29768: Security Bulletin: IBM Cognos Analytics has addressed multiple vulnerabilities

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.

CVE-2022-32535: Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch

The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.

MEGA claims it can’t decrypt your files. But someone’s managed to…

Swiss researchers debunked MEGA's claims that anyone that would be able to take over MEGA's infrastructure would still not have access to your information and files. The post MEGA claims it can’t decrypt your files. But someone’s managed to… appeared first on Malwarebytes Labs.

SAP FRUN Simple Diagnostics Agent 1.0 Directory Traversal

SAP Focused Run Simple Diagnostics Agent version 1.0 suffers from a directory traversal vulnerability.

SAP FRUN Simple Diagnostics Agent 1.0 Information Disclosure

SAP Focused Run Simple Diagnostics Agent version 1.0 suffers from an information disclosure vulnerability.

SAP Fiori Launchpad Cross Site Scripting

The SAP Fiori launchpad suffers from a cross site scripting vulnerability. Various component versions are affected.

SAP FRUN Simple Diagnostics Agent 1.0 Missing Authentication

SAP Focused Run Simple Diagnostics Agent version 1.0 suffers from a missing authentication vulnerability.

SAP FRUN 2.00 / 3.00 Cross Site Scripting

SAP Focused Run versions 2.00 and 3.00 suffer from a cross site scripting vulnerability.