Alerts

Oracle Security Patch Updates – October 2022

Oracle released its critical patch updates for October 2022, containing (370) new security patches for multiple affected products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. This critical patch update provides security updates to fix several vulnerabilities that may be remotely exploitable without authentication in a wide range of

Oracle Security Patch Updates – October 2022 Read More »

IBM Security Updates -18 October 2022

IBM has released security updates to fix several vulnerabilities across multiple products. The severity of the addressed vulnerabilities could allow the remote attacker to expose sensitive information or consume the memory resources of the affected system. Sample of the addressed vulnerabilities : IBM InfoSphere Information Server external entity injection (CVE-2022- 40747) CVSS: 8.2 Attack Vector:

IBM Security Updates -18 October 2022 Read More »

Apache Security Update – 16 October 2022

Apache has released a security Update to address a critical vulnerability in Apache Commons. The remote attacker could exploit this vulnerability to take control of the affected system. Apache Commons Text is vulnerable to code execution caused by an insecure interpolation defaults flaw. The attacker could exploit this vulnerability by sending a specially-crafted input to execute arbitrary

Apache Security Update – 16 October 2022 Read More »

Aruba Released Security Updates – 16 October 2022

Aruba has released security updates for Aruba EdgeConnect Enterprise Orchestrator that address multiple critical security vulnerabilities. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The addressed vulnerabilities could allow the remote attacker to elevate privileges to administrators without credentials and allow arbitrary command execution on the underlying host leading

Aruba Released Security Updates – 16 October 2022 Read More »

Juniper Networks Security Updates – 13 October 2022

Juniper Networks has released multiple security updates to address many vulnerabilities affecting multiple products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system, and cause a denial of service. The most severe of the addressed vulnerabilities could allow the remote authenticated attacker with ‘WRITE’ permissions to store one

Juniper Networks Security Updates – 13 October 2022 Read More »

SAP October 2022 Security Patch Day 12 October 2022

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (2) updates to the previously released patch day security note. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP Manufacturing Execution, SAP Commerce, and SAP BusinessObjects Business Intelligence Platform. The remote attacker could exploit

SAP October 2022 Security Patch Day 12 October 2022 Read More »

Microsoft October 2022 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday, which fixestwo publicly zero-day vulnerabilities, one actively exploited in attacks and one publicly disclosed. Microsoft has fixed (84) vulnerabilities (not including Microsoft Edge vulnerabilities), with (13) classified as Critical as they allow privilege elevation, spoofing, or remote code execution. October’s Patch Tuesday

Microsoft October 2022 Patch Tuesday Read More »

Fortinet Released Security Updates – 10 October 2022

Fortinet has released security updates to address multiple vulnerabilities across multiple products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The highest severity of the addressed vulnerabilities could allow the attacker to execute arbitrary commands in the underlying shell due to multiple improper neutralization of special elements

Fortinet Released Security Updates – 10 October 2022 Read More »

VMware Released Security Updates – 09 October 2022

VMware has released a security advisory to address several vulnerabilities which affect multiple VMware products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system.  The addressed vulnerabilities could allow the attackers to perform several attacks, like executing arbitrary code on the underlying operating system that hosts the vCenter

VMware Released Security Updates – 09 October 2022 Read More »

Trend Micro Released Security Updates – 09 October 2022

Trend Micro has released a new critical patch to address several vulnerabilities in Trend Micro Apex One SP1 and Apex One SaaS. The released security updates resolve several vulnerabilities having severity ratings from medium to critical. The remote attacker could exploit some of these vulnerabilities to gain privileged access to the affected system. Samples of the

Trend Micro Released Security Updates – 09 October 2022 Read More »

Fortinet Released Security Updates – 09 October 2022

Fortinet has released security patches to fix a critical authentication bypass vulnerability across multiple products.  The mentioned vulnerability could allow the remote attacker to bypass security restrictions by sending specially crafted HTTP or HTTPS requests to log into unpatched devices and perform operations on the administrative interface. Fortinet FortiOS and Fortinet FortiProxy security bypass (CVE-2022-40684): •

Fortinet Released Security Updates – 09 October 2022 Read More »

Cisco Released Security Updates – 08 October 2022

Cisco has released security updates to address several vulnerabilities in multiple Cisco products The severity of the addressed vulnerabilities could allow the attacker to fully compromise the Cisco NFVIS system and cause a denial of service. Samples of the addressed vulnerabilities: 1. Cisco Enterprise NFV Infrastructure Software (NFVIS) code execution (CVE 2022-20929): • CVSS: 7.8 •

Cisco Released Security Updates – 08 October 2022 Read More »

Microsoft Edge Security Update – 04 October 2022

Microsoft has released an updated version of Microsoft Edge (Version 106.0.1370.34) to fix a vulnerability in Microsoft Edge. The remote attacker could exploit this vulnerability to take control of the affected system. The severity of the addressed vulnerability could allow the remote attacker to exploit this vulnerability by persuading a victim to visit a specially crafted Web

Microsoft Edge Security Update – 04 October 2022 Read More »