Tag : Vulnerabilities

image_pdfimage_print

German software giant SAP has fixed more than a dozen new vulnerabilities with its August 2023 Patch Tuesday updates, including a critical flaw affecting the company’s PowerDesigner data modeling and enterprise architecture product. SAP released 16 new patches and updated several previously released fixes. The critical (HotNews) PowerDesigner flaw, tracked as CVE-2023-37483, is an improper ..

Leggi tutto

A month after confirming active exploitation of “a series of remote code execution vulnerabilities” impacting Windows and Office users, Microsoft on Tuesday shipped patches for 33 affected products and a “defense in depth update” to block the attack chain. Redmond’s beleaguered security response team said the pre-patch mitigation stops the attack chain leading to the ..

Leggi tutto

Organizations have been warned about a new potentially serious vulnerability affecting the PaperCut NG/MF print management software. The flaw, tracked as CVE-2023-39143 and rated ‘high severity’, can be exploited by unauthenticated attackers to read or write arbitrary files, which could allow remote code execution in certain configurations of the product.  “In particular, the vulnerability affects ..

Leggi tutto

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar. We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape. Each week, we will curate and present ..

Leggi tutto

Multiple vulnerabilities in the popular airline and hotel rewards platform points.com could have allowed attackers to access users’ personal information, security researchers warn. Acting as a backend for numerous airline and hotel rewards programs, points.com also operates as a market for exchanging and redeeming loyalty points. Over the course of several months, security researchers Ian ..

Leggi tutto

Exploitation of the recently disclosed Ivanti Endpoint Manager Mobile (EPMM) vulnerability has started to pick up, just as the vendor announced the discovery of a new flaw. The EPMM zero-day tracked as CVE-2023-35078, which allows an unauthenticated attacker to obtain sensitive information and make changes to the targeted system, was exploited in attacks aimed at ..

Leggi tutto