Aggregator
Всё из-за токенов: Microsoft раскрыла детали IT-хаоса, случившегося на выходных
2 months 3 weeks ago
Администраторы пьют успокоительные, хотя повода для беспокойства и не было.
What school IT admins are up against, and how to help them win
2 months 3 weeks ago
School IT admins are doing tough, important work under difficult conditions. From keeping Wi-Fi stable during exams to locking down systems from phishing emails, their job is part technician, part strategist, part firefighter. But they’re stretched thin. The tools are outdated, the support is missing, and the pressure never stops. Here’s a look at what they’re dealing with and how we can help. What’s holding back school IT Most school tech teams don’t get what … More →
The post What school IT admins are up against, and how to help them win appeared first on Help Net Security.
Anamarija Pogorelec
Lotus Panda Hacks SE Asian Governments With Browser Stealers and Sideloaded Malware
2 months 3 weeks ago
The China-linked cyber espionage group tracked as Lotus Panda has been attributed to a campaign that compromised multiple organizations in an unnamed Southeast Asian country between August 2024 and February 2025.
"Targets included a government ministry, an air traffic control organization, a telecoms operator, and a construction company," the Symantec Threat Hunter Team said in a new report
The Hacker News
CVE-2022-46353 | Siemens SCALANCE X204RNA up to 3.2.6 random values (ssa-363821)
2 months 3 weeks ago
A vulnerability classified as problematic has been found in Siemens SCALANCE X204RNA up to 3.2.6. Affected is an unknown function. The manipulation leads to insufficiently random values.
This vulnerability is traded as CVE-2022-46353. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46352 | Siemens SCALANCE X204RNA/SCALANCE X204RNA EEC prior 3.2.7 PROFINET DCP Packet resource consumption (ssa-363821)
2 months 3 weeks ago
A vulnerability classified as problematic has been found in Siemens SCALANCE X204RNA and SCALANCE X204RNA EEC. This affects an unknown part of the component PROFINET DCP Packet Handler. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2022-46352. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46351 | Siemens SCALANCE X204RNA/SCALANCE X204RNA EEC prior 3.2.7 PROFINET DCP Packet denial of service (ssa-363821)
2 months 3 weeks ago
A vulnerability classified as problematic was found in Siemens SCALANCE X204RNA and SCALANCE X204RNA EEC. Affected by this vulnerability is an unknown functionality of the component PROFINET DCP Packet Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2022-46351. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46350 | Siemens SCALANCE X204RNA/SCALANCE X204RNA EEC prior 3.2.7 Integrated Web Server cross site scripting (ssa-363821)
2 months 3 weeks ago
A vulnerability has been found in Siemens SCALANCE X204RNA and SCALANCE X204RNA EEC and classified as problematic. This vulnerability affects unknown code of the component Integrated Web Server. The manipulation leads to basic cross site scripting.
This vulnerability was named CVE-2022-46350. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46062 | Gym Management System 0.0.1 cross-site request forgery
2 months 3 weeks ago
A vulnerability classified as problematic was found in Gym Management System 0.0.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2022-46062. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Apache CXF up to 3.4.9/3.5.4 MTOM Request XOP:Include server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability has been found in Apache CXF up to 3.4.9/3.5.4 and classified as critical. This vulnerability affects the function XOP:Include of the component MTOM Request Handler. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2022-46364. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46364 | Oracle Communications Diameter Signaling Router 8.6.0.0 Virtual Network Function Manager server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability classified as very critical has been found in Oracle Communications Diameter Signaling Router 8.6.0.0. Affected is an unknown function of the component Virtual Network Function Manager. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-46364. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Communications Element Manager 9.0.0/9.0.1 SOAP server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability, which was classified as very critical, was found in Oracle Communications Element Manager 9.0.0/9.0.1. This affects an unknown part of the component SOAP. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2022-46364. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Communications Session Report Manager 9.0.0/9.0.1 SOAP server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability classified as very critical has been found in Oracle Communications Session Report Manager 9.0.0/9.0.1. This affects an unknown part of the component SOAP. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2022-46364. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Banking Digital Experience 21.1/22.1/22.2 UI General server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability was found in Oracle Banking Digital Experience 21.1/22.1/22.2. It has been rated as very critical. Affected by this issue is some unknown functionality of the component UI General. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2022-46364. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Communications Messaging Server 8.1.0.21.0 Messaging Store server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability classified as very critical has been found in Oracle Communications Messaging Server 8.1.0.21.0. Affected is an unknown function of the component Messaging Store. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-46364. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Banking Cash Management 14.7.0.2.0/14.7.1.0.0 Accessibility server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability was found in Oracle Banking Cash Management 14.7.0.2.0/14.7.1.0.0. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component Accessibility. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2022-46364. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Banking Corporate Lending Process Management 14.4/14.5/14.6/14.7 Base server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability classified as very critical has been found in Oracle Banking Corporate Lending Process Management 14.4/14.5/14.6/14.7. This affects an unknown part of the component Base. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2022-46364. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Banking Credit Facilities Process Management 14.7.1.0.0 Common server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability classified as very critical was found in Oracle Banking Credit Facilities Process Management 14.7.1.0.0. This vulnerability affects unknown code of the component Common. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2022-46364. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-46364 | Oracle Banking Liquidity Management 14.5.0.8.0/14.6.0.4.0/14.7.0.2.0/14.7.1.0.0 Common server-side request forgery (Nessus ID 211909)
2 months 3 weeks ago
A vulnerability, which was classified as very critical, was found in Oracle Banking Liquidity Management 14.5.0.8.0/14.6.0.4.0/14.7.0.2.0/14.7.1.0.0. Affected is an unknown function of the component Common. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-46364. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
三星One UI安全漏洞:剪贴板数据明文存储且永不过期
2 months 3 weeks ago
三星One UI剪贴板漏洞致用户敏感数据永久明文存储,数百万设备面临泄露风险!