Sophos Research Uncovers Widespread Use of TLS By Cybercriminals

Sophos Research Uncovers Widespread Use of TLS By Cybercriminals
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2021-33516PUBLISHED: 2021-05-24

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected servic...

CVE-2020-4990PUBLISHED: 2021-05-24

IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.

CVE-2021-20385PUBLISHED: 2021-05-24

IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 195766.

CVE-2021-20386PUBLISHED: 2021-05-24

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195767.

CVE-2021-20389PUBLISHED: 2021-05-24

IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.




Support the originator by clicking the read the rest link below.