CVE-2022-24500 Windows SMB Remote Code Execution Vulnerability.
This vulnerability affects Windows client and server operating systems. It can be exploited by malicious users to install arbitrary code in vulnerable computers. This attack
CVE-2022-1258 An authenticated administrator on ePO can exploit a blind SQL injection vulnerability in MA ePO 5.7.6 and perform arbitrary SQL queries in the back-end database. This can lead to command execution.
An attacker must first obtain the ability to access the ePO server and then perform a series of steps to exploit this vulnerability. First, the
CVE-2022-0552 A flaw was found in the fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete.
A new version has been released to fix this issue. The new maven package is origin-aggregated-logging-3.12. The updated image is available
CVE-2022-24681 ADS SelfService Plus before 6.12 has XSS that allows reset password, unlock account, or user must change password.
XSS is an injection vulnerability where code is injected into one web application component and executed in another component’s context. This can lead to
CVE-2022-23970 The update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter.
An attacker can create a specially-crafted update_json HTTP request that causes the update_json function to load a different file than it normally
Episode
00:00:00
00:00:00