IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
Category Archives: Advisories
java-latest-openjdk-18.0.2.0.9-1.rolling.el9
FEDORA-EPEL-2022-3bd4c9e300
Packages in this update:
java-latest-openjdk-18.0.2.0.9-1.rolling.el9
Update description:
July CPU update
java-latest-openjdk-18.0.2.0.9-1.rolling.el8
FEDORA-EPEL-2022-73672e02b0
Packages in this update:
java-latest-openjdk-18.0.2.0.9-1.rolling.el8
Update description:
July CPU update
python3.11-3.11.0~rc2-1.fc36
FEDORA-2022-0b3904c674
Packages in this update:
python3.11-3.11.0~rc2-1.fc36
Update description:
Update Python to 3.11.0rc2. Contains security fix for CVE-2020-10735 and other bugfixes, see https://docs.python.org/3.11/whatsnew/changelog.html#python-3-11-0-release-candidate-2
freeipa-4.10.0-6.fc37 samba-4.17.0-1.fc37
FEDORA-2022-4555909843
Packages in this update:
freeipa-4.10.0-6.fc37
samba-4.17.0-1.fc37
Update description:
Update to version 4.17.0
ZDI-22-1191: Trend Micro Apex One Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ZDI-22-1190: Trend Micro Apex One Security Agent Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ZDI-22-1189: Trend Micro Apex One Origin Validation Error Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ZDI-22-1219: (0Day) NIKON NIS-Elements Viewer TIF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
ZDI-22-1218: (0Day) NIKON NIS-Elements Viewer TIF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.