IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 206089
Category Archives: Advisories
exim-4.96-2.fc35
FEDORA-2022-1ca1d22165
Packages in this update:
exim-4.96-2.fc35
Update description:
This is update of exim to fix CVE-2022-37451.
exim-4.96-2.fc36
FEDORA-2022-f9a8388e62
Packages in this update:
exim-4.96-2.fc36
Update description:
This is update of exim to fix CVE-2022-37451.
mingw-jasper-3.0.6-2.fc37
FEDORA-2022-b38fbc239b
Packages in this update:
mingw-jasper-3.0.6-2.fc37
Update description:
Backport fix for CVE-2022-2963.
insight-13.0.50.20220502-1.fc35
FEDORA-2022-8e1df11a7a
Packages in this update:
insight-13.0.50.20220502-1.fc35
Update description:
New upstream snapshot.
Fixes CVE-2021-3826.
Disable deprecated declaration warnings/errors.
Disable nonnull-compare warnings.
Patch “symtab_no_format_overflow” to avoid a false positive format overflow
detection.
FreeBSD-EN-22:20.tzdata
DSA-5222 dpdk – security update
A buffer overflow was discovered in the vhost code of DPDK,
a set of libraries for fast packet processing, which could result
in denial of service or the execution of arbitrary code by malicious
guests/containers.
CVE-2020-26938
In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern (“[a-zA-Z][a-zA-Z0-9+.-]+:”) before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.
CVE-2021-38934
IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210671.
rubygem-puma-4.3.6-5.fc35
FEDORA-2022-de968d1b6c
Packages in this update:
rubygem-puma-4.3.6-5.fc35
Update description:
Fix CVE-2022-23634 – information leak between requests.
Fix CVE-2022-24790 – http request smuggling vulnerabilities