German enterprise software maker SAP this week announced the release of 18 new security notes on its May 2023 Security Patch Day, including two ‘hot news’ notes that deal with critical vulnerabilities. One of the hot news notes resolves five vulnerabilities in the Reprise License Manager (RLM) 14.2 component of SAP 3D Visual Enterprise License ..
Tag : Vulnerabilities
Microsoft on Tuesday announced patches for 40 newly documented vulnerabilities in its products, including two zero-day flaws. One of the zero-days, CVE-2023-29336, is described as an elevation of privilege bug in the Win32k driver. Successful exploitation could allow an attacker to gain System privileges. Microsoft has shared no information on the attacks exploiting this vulnerability, ..
Adobe has announced security updates for its Substance 3D Painter product to address more than a dozen vulnerabilities. This is the only product for which the software giant released updates this Patch Tuesday. According to Adobe, the 3D painting software, specifically version 8.3.0 and earlier, is impacted by 14 vulnerabilities. A vast majority are high-severity ..
A cross-site scripting (XSS) vulnerability in the Advanced Custom Fields WordPress plugin could be exploited to inject malicious scripts into websites. Tracked as CVE-2023-30777, the vulnerability impacts both the free and paid versions of the plugin. Advanced Custom Fields has more than 2 million installs via the official WordPress app store. The plugin provides site ..
Fortinet this week announced its monthly set of security updates that address nine vulnerabilities in multiple products, including two high-severity bugs in FortiADC, FortiOS, and FortiProxy. Impacting the FortiADC application delivery controller, the most severe of these issues is tracked as CVE-2023-27999 and is described as “an improper neutralization of special elements used in an ..
Three vulnerabilities in the Azure API Management service could be exploited to perform various types of malicious actions, cloud security company Ermetic reveals. A fully managed platform, the Azure API Management service allows organizations to manage, analyze, and secure APIs across environments, making them available to developers, employees, and partners. The identified vulnerabilities, two server-side ..
Google’s Android security updates for May 2023 patch more than 40 vulnerabilities, including a kernel flaw exploited as a zero-day by a spyware vendor. The latest Android updates patch vulnerabilities in the framework, system, kernel, Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm components. A vast majority of the security holes have been assigned a ‘high ..
Cisco this week raised the alarm on a critical remote code execution (RCE) vulnerability impacting SPA112 2-Port phone adapters, which have reached end-of-life (EoL) status. Tracked as CVE-2023-20126 (CVSS score of 9.8), the flaw impacts the web-based management interface of the phone adapters and can be exploited without authentication. The issue, Cisco explains in its ..
Apple has released the first-ever security updates for its Beats and AirPods products to patch a vulnerability that can be exploited to gain access to headphones through a Bluetooth attack. The flaw is tracked as CVE-2023-27964 and it was reported to Apple by Yun-hao Chung and Archie Pusaka of Google ChromeOS. The vulnerability has been ..
A widely used BGP implementation is affected by three vulnerabilities that can be exploited to cause disruption through denial-of-service (DoS) attacks, according to cybersecurity firm Forescout. The Border Gateway Protocol (BGP) plays an important role in the way the internet works. It serves as the main routing protocol, allowing autonomous systems (AS) — networks or ..


