[FD] SEC Consult SA-20240307-0 :: Local Privilege Escalation via writable files in Checkmk Agent (CVE-2024-0670)

2024-03-13 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
nd us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-co

[FD] SEC Consult SA-20240226-0 :: Local Privilege Escalation via DLL Hijacking in Qognify VMS Client Viewer

2024-03-02 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
~ Mail: security-research at sec-consult dot com Web: https://www.sec-consult.com Blog: https://blog.sec-consult.com Twitter: https://twitter.com/sec_consult EOF Sandro Einfeldt / @2024 ___ Sent through the F

[FD] SEC Consult SA-20240220-0 :: Multiple Stored Cross-Site Scripting Vulnerabilities in OpenOLAT (Frentix GmbH)

2024-02-20 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
r customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-c

[FD] SEC Consult SA-20240212-0 :: Multiple Stored Cross-Site Scripting vulnerabilities in Statamic CMS

2024-02-13 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~

[FD] SEC Consult SA-20231211-0 :: Local Privilege Escalation via MSI installer in PDF24 Creator

2023-12-12 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
rested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/

[FD] SEC Consult SA-20231206 :: Kiosk Escape Privilege Escalation in One Identity Password Manager Secure Password Extension

2023-12-12 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
s of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: securit

[FD] SEC Consult SA-20231205 :: Argument injection leading to unauthenticated RCE and authentication bypass in Atos Unify OpenScape Session Border Controller (SBC), Branch, BCF

2023-12-12 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
mation about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC

[FD] SEC Consult SA-20231005 :: Open Redirect in SAP® BSP Test Application it00 (Bypass for CVE-2020-6215 Patch)

2023-10-05 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: https://www.sec-consult.com Blog: https://blog.sec-consult.com Twitter: https://twitter.com/sec_consult E

[FD] SEC Consult SA-20230927-0 :: Multiple Vulnerabilities in SAP® Enable Now Manager

2023-10-02 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
valuation of new offensive and defensive technologies for our customers. Hence our customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~ Interested to work wit

[FD] SEC Consult SA-20230925-0 :: Stored Cross-Site Scripting in mb Support broker management solution openVIVA c2

2023-10-02 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-cons

[FD] SEC Consult SA-20230918-0 :: Authenticated Remote Code Execution and Missing Authentication in Atos Unify OpenScape

2023-09-18 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
our application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult d

[FD] SEC Consult SA-20230829-0 :: Reflected Cross-Site Scripting (XSS) in PTC - Codebeamer (ALM Solution)

2023-09-18 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20230829-0 > === title: Reflected Cross-Site Scripting (XSS) product: PTC - Codebeamer (ALM Solution) vulnerable version: <=22.10-SP7, <=22.04-SP5, <=2

[FD] SEC Consult SA-20230705-0 :: Path traversal bypass & Denial of service in Kyocera TASKalfa 4053ci printer

2023-07-07 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
ation https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: ht

[FD] SEC Consult SA-20230703-0 :: Multiple Vulnerabilities including Unauthenticated RCE in Siemens A8000

2023-07-07 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
end us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: secu

[FD] SEC Consult Vulnerability Lab Whitepaper: Everyone Knows SAP®, Everyone Uses SAP, Everyone Uses RFC, No One Knows RFC: From RFC to RCE 16 Years Later

2023-07-07 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
a set of high-impact implementation bugs and design flaws were identified by SEC Consult Vulnerability Lab security researcher and SAP security expert Fabian Hagg. Technical details about the research results are presented during the annual Troopers Security Conference 2023 in Heidelberg, G

[FD] SEC Consult SA-20230628-0 :: Stored XSS & Privilege Escalation in Boomerang Parental Control App

2023-07-07 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
hnologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices h

[FD] SEC Consult SA-20230627-0 :: Multiple high risk vulnerabilities in ILIAS eLearning platform

2023-07-07 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
ich mitigate the identified vulnerabilities. Vulnerability 1) is fixed in versions or higher: 7.22, 8.3 Vulnerability 2) is fixed in versions or higher: 6.22, 7.18, 8.0 Vulnerability 3) is fixed in versions or higher: 6.23, 7.19, 8.0 The patches can be downloaded from the vendor's website wh

[FD] SEC Consult SA-20230517-0 :: Stored XSS vulnerability in rename functionality in Wekan (Open-Source kanban)

2023-05-29 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
ttps://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web

[FD] SEC Consult SA-20230516-0 :: Multiple Vulnerabilities in Serenity and StartSharp Software

2023-05-29 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/c

[FD] SEC Consult SA-20230515-0 :: Multiple Vulnerabilities in Kiddoware Kids Place Parental Control Android App

2023-05-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
s and valid recommendation about the risk profile of new technologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber

[FD] SEC Consult SA-20230502-0 :: Bypassing cluster isolation through insecure defaults and shared storage in Databricks Platform

2023-05-02 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
an atos business Europe | Asia | North America About SEC Consult Vulnerability Lab The SEC Consult Vulnerability Lab is an integrated part of SEC Consult, part of Eviden, an atos business. It ensures the continued knowledge gain of SEC Consult in the field of network and application security to st

[FD] [CVE-2023-25355/25356] No fix available - vulnerabilities in CoreDial sipXcom sipXopenfire

2023-03-06 Thread Systems Research Group via Fulldisclosure
_ ¯¯¯\__/ ༼ つ ◕_◕ ༽つ (ง'̀-'́)ง(╯°□°)╯︵ ┻━┻ ヽ(´ー`)ノ \__/¯¯ ¯ Product: sipXcom sipXopenfire Vendor: CoreDial Name: "sipXcom sipXopenfire XMP

[FD] SEC Consult SA-20230306-0 :: Multiple Vulnerabilities in Arris DG3450 Cable Gateway

2023-03-06 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
rts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-

[FD] SEC Consult SA-20230228-0 :: OS Command Injectionin Barracuda CloudGen WAN

2023-03-02 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
. Hence our customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber se

[FD] SEC Consult SA-20230117-2 :: Multiple post-authentication vulnerabilities including RCE in @OpenText Content Server component of OpenText Extended ECM

2023-01-19 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
* CVE-2022-45928: 16.2.2 - 22.3 Vendor contact timeline: 2022-10-07: Vendor contacted via secur...@opentext.com 2022-10-07: Vendor acknowledged the email and is reviewing the reports 2022-11-18: Vendor confirms all vulnerabilities and is working on a patch aimed to

[FD] SEC Consult SA-20230117-1 :: Pre-authenticated Remote Code Execution via Java frontend and QDS endpoint in @OpenText Content Server component of OpenText Extended ECM

2023-01-19 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
--- 2022-10-07: Vendor contacted via secur...@opentext.com 2022-10-07: Vendor acknowledged the email and is reviewing the reports 2022-11-18: Vendor confirms all vulnerabilities and is working on a patch aimed to be released in November 2022-11-24: Vendor delays t

[FD] SEC Consult SA-20230117-0 :: Pre-authenticated Remote Code Execution in cs.exe (@OpenText Content Server component of OpenText Extended ECM)

2023-01-19 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
fensive and defensive technologies for our customers. Hence our customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~ Interested to work with the

[FD] SEC Consult SA-20221216-0 :: Remote code execution bypass in Eclipse Business Intelligence Reporting Tool (BiRT)

2022-12-20 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at

[FD] SEC Consult Vulnerability Lab publication: The enemy from within: Unauthenticated Buffer Overflows in Zyxel routers still haunting users & metasploit exploit

2022-12-20 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.com Twitter:

[FD] SEC Consult SA-20221213-0 :: Privilege Escalation Vulnerabilities (UNIX Insecure File Handling) in SAP Host Agent (saposcol)

2022-12-13 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
new technologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local off

[FD] SEC Consult SA-20221206-0 :: Multiple critical vulnerabilities in ILIAS eLearning platform

2022-12-08 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20221206-0 > === title: Multiple critical vulnerabilities product: ILIAS eLearning platform vulnerable version: <= 7.15 fixed version: 7.16

[FD] SEC Consult SA-20221201-0 :: Replay attacks & Displaying arbitrary contents in Zhuhai Suny Technology ESL Tag / ETAG-TECH protocol (electronic shelf labels)

2022-12-08 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
ther security issues. The research has also been presented at various security conferences such as hardwear.io, named "Self-labeling electronic shelf labels". Vulnerability overview/description: --- 1) Replay Attack The displayed information on the price ta

[FD] SEC Consult SA-20221114-0 :: Path Traversal Vulnerability in Payara Platform

2022-11-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
our cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-c

[FD] SEC Consult SA-20221110-0 :: HTML Injection in BMC Remedy ITSM-Suite

2022-11-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20221110-0 > === title: HTML Injection product: BMC Remedy ITSM-Suite vulnerable version: 9.1.10 (= 20.02 in new versioning scheme) fixed versio

[FD] SEC Consult SA-20221109-0 :: Multiple Critical Vulnerabilities in Simmeth System GmbH Supplier manager (Lieferantenmanager)

2022-11-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
at patching customers will take until end of July. 2022-09-02: Asking about CVE numbers and if all customers are patched. 2022-09-05: Some customers are not yet patched. Current version is phased out by the end of september. All customers will have to upgrade until then. SEC Consult will req

[FD] SEC Consult SA-20220923-0 :: Multiple Memory Corruption Vulnerabilities in COVESA (Connected Vehicle Systems Alliance) DLT daemon

2022-09-27 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: securi

[FD] SEC Consult SA-20220915-0 :: Local Privilege Escalation im SAP® SAPControl Web Service Interface (sapuxuserchk)

2022-09-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
d recommendation about the risk profile of new technologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the e

[FD] SEC Consult SA-20220914-0 :: Improper Access Control in SAP® SAProuter

2022-09-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
erts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail:

[FD] Onapsis Security Advisory 2022-0007: Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)

2022-06-21 Thread Onapsis Research via Fulldisclosure
- Onapsis blogpost: https://onapsis.com/blog/sap-security-patch-day-april-2022-focus-spring4shell-an d-sap-mii - CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27657 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3159091 ## About Onapsis Research Labs Onapsis Research

[FD] Onapsis Security Advisory 2022-0006: Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)

2022-06-21 Thread Onapsis Research via Fulldisclosure
-focused-run-affec ted-several-vulnerabilities - CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22547 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3147102 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that

[FD] Onapsis Security Advisory 2022-0005: Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad

2022-06-21 Thread Onapsis Research via Fulldisclosure
57089 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-

[FD] # Onapsis Security Advisory 2022-0004: Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)

2022-06-21 Thread Onapsis Research via Fulldisclosure
Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge

[FD] Onapsis Security Advisory 2022-0003: Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)

2022-06-21 Thread Onapsis Research via Fulldisclosure
?name=CVE-2022-24399 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3147283 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely securit

[FD] SEC Consult SA-20220615-0 :: Hardcoded Backdoor User and Outdated Software Components in Nexans FTTO GigaSwitch series

2022-06-17 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
ologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~

[FD] SEC Consult SA-20220614-0 :: Reflected Cross Site Scripting in SIEMENS-SINEMA Remote Connect

2022-06-14 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
ity with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.

[FD] SEC Consult SA-20220609-0 :: Multiple vulnerabilities in SoftGuard SNMP Network Management Extension

2022-06-11 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: https://www

[FD] SEC Consult SA-20220608-0 :: Stored Cross-Site Scripting & Unsafe Java Deserializiation in Gentics CMS

2022-06-11 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20220608-0 > === title: Stored Cross-Site Scripting & Unsafe Java Deserializiation product: Gentics CMS vulnerable version: 5.36.29, see section below

[FD] SEC Consult SA-20220607-0 :: Multiple Vulnerabilities in Infiray IRAY-A8Z3 thermal camera

2022-06-11 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: http

[FD] SEC Consult SA-20220602-0 :: Multiple Memory Corruption Vulnerabilities in dbus-broker

2022-06-03 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
he experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~

[FD] SEC Consult SA-20220601-1 :: Authenticated Command Injection in Poly Studio

2022-06-03 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.com Twitter: https://twitter.com/sec_consult

[FD] SEC Consult SA-20220601-0 :: Multiple Critical Vulnerabilities in Poly EagleEye Director II

2022-06-03 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
es for our customers. Hence our customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.c

[FD] SEC Consult SA-20220531-0 :: Backdoor account in Korenix JetPort 5601V3

2022-06-03 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
erested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot com Web: https://www.sec-c

[FD] SEC Consult SA-20220518-0 :: Multiple Critical Vulnerabilities in SAP® Application Server, ABAP and ABAP® Platform (Different Software Components)

2022-05-18 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~

[FD] SEC Consult SA-20220505-0 :: Password Reset Poisoning Attack in Craft CMS

2022-05-05 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
lication https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: security-research at sec-consult dot c

[FD] Onapsis Security Advisory 2022-0002: Denial of Service in SAP NetWeaver JAVA

2022-05-04 Thread Onapsis Research via Fulldisclosure
://onapsis.com/blog/sap-security-patch-day-july-2021-serious-vulnerabilities-sap-netweaver-java-fixed - CVE Mitre: https://nvd.nist.gov/vuln/detail/CVE-2021-33670 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3056652 ## About Onapsis Research Labs Onapsis Research Labs provides the industry

[FD] Onapsis Security Advisory 2022-0001: HTTP Request Smuggling in SAP Web Dispatcher

2022-05-04 Thread Onapsis Research via Fulldisclosure
n/cvename.cgi?name=CVE-2021-38162 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3080567 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and com

[FD] SEC Consult SA-20220427-0 :: Privilege Escalation in Miele Benchmark Programming Tool

2022-04-27 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~~

[FD] SEC Consult SA-20220413 :: Missing Authentication at File Download & Denial of Service in Siemens A8000 PLC

2022-04-14 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
by: SEC Consult Vulnerability Lab This vulnerability was discovered during the research cooperation initiative "OT Cyber Security Lab" between Verbund AG and SEC Consult Group. Stef

[FD] SEC Consult SA-20220215 :: Multiple Critical Vulnerabilities in multiple Zyxel devices

2022-02-16 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
- def decrypt_zyxel_encrypt(input): key=bytearray.fromhex( 'XX') iv=bytearray.fromhex('') input=input.replace('_encrypt_','') decoded = b64decode(inp

[FD] Finding secrets in mirrored Git repositories

2022-02-13 Thread Nightwatch Cybersecurity Research
/nightwatchcybersecurity/gb_testrepo_reset TOOLING There are plenty of existing tools out there that can manipulate git repositories, scan them for secrets and remove specific commits. During our research, we used git for checking out repositories, git-filter-repo for figuring out the delta

[FD] SEC Consult SA-20220209 :: Open Redirect in Login Page in SIEMENS-SINEMA Remote Connect

2022-02-10 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
oving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.co

[FD] SEC Consult SA-20220202-0 :: Broken access control & Cross-Site Scripting in Shopmetrics Mystery Shopping Software

2022-02-03 Thread SEC Consult Vulnerability Lab, Research
onsult.com === Vendor description: --- "Founded in 2004, Shopmetrics is a company that offers technology platform solutions to mystery shopping and market research providers worldwide. Today Shopmetrics is a global organization with offices in North America and Europe. Wi

[FD] SEC Consult SA-20220131-0 :: Multiple Critical Vulnerabilities in Korenix Technology JetWave products

2022-02-03 Thread SEC Consult Vulnerability Lab, Research
~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~

[FD] SEC Consult SA-20220126-0 :: Denial of service & User Enumeration in WAGO 750-8xxx PLC

2022-02-03 Thread SEC Consult Vulnerability Lab, Research
re discovered during the research cooperation initiative "OT Cyber Security Lab" between Verbund AG and SEC Consult Group. Gerhard Hechenberger (Office Vienna) Steffen Robertz (Office Vienna)

[FD] Onapsis Security Advisory 2021-0026: SAP Enterprise Portal - XSLT injection

2022-01-26 Thread Onapsis Research via Fulldisclosure
i-bin/cvename.cgi?name=CVE-2021-37531 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3081888 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and t

[FD] Onapsis Security Advisory 2021-0025: Null Pointer Dereference vulnerability in SAP CommonCryptoLib

2022-01-26 Thread Onapsis Research via Fulldisclosure
Note fixing the issue ## References - Onapsis blogpost: https://www.onapsis.com/blog/sap-security-patch-day-september-2021 - CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38177 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3051787 ## About Onapsis Research Labs

[FD] Onapsis Security Advisory 2021-0024: SAP Enterprise Portal - Anonymous Stored Open Redirect

2022-01-26 Thread Onapsis Research via Fulldisclosure
tch: https://launchpad.support.sap.com/#/notes/3076399 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk level

[FD] Onapsis Security Advisory 2021-0023: SAP Enterprise Portal - SSRF iviewCatcherEditor

2022-01-26 Thread Onapsis Research via Fulldisclosure
issue. ## References - Onapsis blogpost: https://www.onapsis.com/blog/sap-security-patch-day-august-2021 - CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33705 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3074844 ## About Onapsis Research Labs Onapsis Research

[FD] Onapsis Security Advisory 2021-0022: SAP Enterprise Portal - XSS RunContentCreation

2022-01-26 Thread Onapsis Research via Fulldisclosure
## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth kno

[FD] Onapsis Security Advisory 2021-0021: SAP Enterprise Portal - XSS NavigationReporter

2022-01-26 Thread Onapsis Research via Fulldisclosure
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33702 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3059764 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Deliv

[FD] SEC Consult SA-20220124-0 :: Authenticated Path Traversal in Ethercreative Logs plugin for Craft CMS

2022-01-24 Thread SEC Consult Vulnerability Lab, Research
tion testing and the evaluation of new offensive and defensive technologies for our customers. Hence our customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~~~

[FD] SEC Consult SA-20220120-0 :: Local file inclusion vulnerability in Land Software - FAUST iServer

2022-01-24 Thread SEC Consult Vulnerability Lab, Research
ntact our local offices https://sec-consult.com/contact/ ~~~ Mail: research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.com Twitter: https://twitter.com/sec_consult EOF Mario Keck / @2022

[FD] SEC Consult SA-20220117-0 :: Stored Cross-Site Scripting vulnerability in TYPO3 extension "femanager"

2022-01-24 Thread SEC Consult Vulnerability Lab, Research
~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.co

[FD] SEC Consult SA-20220113-0 :: Cleartext Storage of Phone Password in Cisco IP Phones

2022-01-14 Thread SEC Consult Vulnerability Lab, Research
ity with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~ Mail: research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.com Twitter: https://twitter.co

[FD] Onapsis Security Advisory 2021-0020: SAP Enterprise Portal - Exposed sensitive data in html body

2021-10-22 Thread Onapsis Research via Fulldisclosure
## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth

[FD] Onapsis Security Advisory 2021-0019: [Multiple CVEs] Memory Corruption vulnerability in SAP NetWeaver ABAP IGS service

2021-10-22 Thread Onapsis Research via Fulldisclosure
/cvename.cgi?name=CVE-2021-27626 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27627 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3021050 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical

[FD] Onapsis Security Advisory 2021-0018: [Multiple CVEs] Memory Corruption vulnerability in SAP NetWeaver ABAP Gateway service

2021-10-22 Thread Onapsis Research via Fulldisclosure
://launchpad.support.sap.com/#/notes/3020209 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis

[FD] Onapsis Security Advisory 2021-0017: [Multiple CVEs] Memory Corruption vulnerability in SAP NetWeaver ABAP Enqueue service

2021-10-22 Thread Onapsis Research via Fulldisclosure
-2021-27632 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3020104 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance

[FD] Onapsis Security Advisory 2021-0016: XXE in SAP JAVA NetWeaver System Connections

2021-10-22 Thread Onapsis Research via Fulldisclosure
://launchpad.support.sap.com/#/notes/3053066 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis

[FD] Onapsis Security Advisory 2021-0015: [Multiple CVEs] Memory Corruption vulnerability in SAP NetWeaver ABAP Dispatcher service

2021-10-22 Thread Onapsis Research via Fulldisclosure
/cvename.cgi?name=CVE-2021-27607 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27628 - Vendor Patch: https://launchpad.support.sap.com/#/notes/3021197 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems

[FD] Onapsis Security Advisory 2021-0014: Missing authorization check in SAP Solution Manager LM-SERVICE Component SP 11 PL 2

2021-06-14 Thread Onapsis Research via Fulldisclosure
note 2890213 fixing this issue ## References - Onapsis blogpost: https://onapsis.com/blog/sap-security-notes-september-2020 - CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6207 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2890213 ## About Onapsis Research Labs

[FD] Onapsis Security Advisory 2021-0013: [CVE-2020-26829] - Missing Authentication Check In SAP NetWeaver AS JAVA P2P Cluster communication

2021-06-14 Thread Onapsis Research via Fulldisclosure
://launchpad.support.sap.com/#/notes/2974774 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels

[FD] Onapsis Security Advisory 2021-0012: SAP Manufacturing Integration and Intelligence lack of server side validations leads to RCE

2021-06-14 Thread Onapsis Research via Fulldisclosure
psis.com/blog/sap-security-notes-march-2021 * CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21480 * Vendor Patch: https://launchpad.support.sap.com/#/notes/3022622 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues tha

[FD] Onapsis Security Advisory 2021-0011 Missing authorization check in SolMan End-User Experience Monitoring

2021-06-14 Thread Onapsis Research via Fulldisclosure
submission. - 12/08/2020 - SAP releases note. ## References - Onapsis blogpost: https://onapsis.com/blog/sap-security-notes-december-2020 - CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26830 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2983204. ## About O

[FD] Onapsis Security Advisory 2021-0010: File exfiltration and DoS in SolMan End-User Experience Monitoring

2021-06-14 Thread Onapsis Research via Fulldisclosure
ve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26837 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2983204. ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering

[FD] Onapsis Security Advisory 2021-0009: Hard-coded Credentials in CA Introscope Enterprise Manager

2021-06-14 Thread Onapsis Research via Fulldisclosure
rg/cgi-bin/cvename.cgi?name=CVE-2020-6369 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2971638 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely se

[FD] Onapsis Security Advisory 2021-0008: OS Command Injection in CA Introscope Enterprise Manager

2021-06-14 Thread Onapsis Research via Fulldisclosure
E Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6364 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2969828 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Deliverin

[FD] Onapsis Security Advisory 2021-0007: Exposure of Sensitive Information to an Unauthorized Actor

2021-06-14 Thread Onapsis Research via Fulldisclosure
ote fixing the issue. Vulnerability is now closed ## References * Onapsis blogpost: https://onapsis.com/blog/sap-security-notes-november-2020 * CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26809 * Vendor Patch: https://launchpad.support.sap.com/#/notes/2975189 ## About Onapsis Re

[FD] Onapsis Security Advisory 2021-0006: [CVE-2020-26811] - SAP Hybris eCommerce - SSRF in acceleratorservices module

2021-06-14 Thread Onapsis Research via Fulldisclosure
26811 * Vendor Patch: https://launchpad.support.sap.com/#/notes/2975170 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance adviso

[FD] Onapsis Security Advisory 2021-0005: SAP Solution Manager Open Redirect from Trace Analysis

2021-06-14 Thread Onapsis Research via Fulldisclosure
psis blogpost: https://onapsis.com/blog/sap-security-notes-december-2020 - CVE Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26836 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2938650 ## About Onapsis Research Labs Onapsis Research Labs provides the industry anal

[FD] [KIS-2021-04] IPS Community Suite <= 4.5.4.2 (previewBlock) PHP Code Injection Vulnerability

2021-05-28 Thread research
-- IPS Community Suite <= 4.5.4.2 (previewBlock) PHP Code Injection Vulnerability -- [-] Software Link: https://invisioncommunity.com [-] A

[FD] Supply Chain Attacks via GitHub.com Releases

2021-04-27 Thread Nightwatch Cybersecurity Research
(Original blog post here: https://wwws.nightwatchcybersecurity.com/2021/04/25/supply-chain-attacks-via-github-com-releases/) SUMMARY Release functionality on GitHub.com allows modification of assets within a release by any project collaborator. This can occur after the release is published, and w

[FD] [CVE-2021-20989, CVE-2021-20990, CVE-2021-20991, CVE-2021-20992] Multiple vulnerabilities in Fibaro Home Center

2021-04-19 Thread research
IoT Inspector Research Lab Advisory IOT-20210408-0 ~~~ title: Multiple vulnerabilities vendor/product: Fibaro Home Center Light / Fibaro Home Center 2 https://www.fibaro.com

[FD] Onapsis Security Advisory 2021-0004: [CVE-2020-26820] - SAP Java OS Remote Code Execution

2021-04-05 Thread Onapsis Research via Fulldisclosure
tre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26820 * Vendor Patch: https://launchpad.support.sap.com/#/notes/2979062 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications.

[FD] Onapsis Security Advisory 2021-0003: [CVE-2020-6287] - [SAP RECON] SAP JAVA: Unauthenticated execution of configuration tasks

2021-04-05 Thread Onapsis Research via Fulldisclosure
sap.com/#/notes/2947895 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Resear

[FD] Onapsis Security Advisory 2021-0002: [CVE-2020-6234] - SAP Multiple root LPE through SAP Host Control

2021-04-05 Thread Onapsis Research via Fulldisclosure
020-6234 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2902645 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated

[FD] Onapsis Security Advisory 2021-0001: [CVE-2020-6207] - Unauthenticated RCE in SAP all SMD Agents connected to SAP SolMan

2021-04-05 Thread Onapsis Research via Fulldisclosure
/cvename.cgi?name=CVE-2020-6207 - Vendor Patch: https://launchpad.support.sap.com/#/notes/2890213 ## About Onapsis Research Labs Onapsis Research Labs provides the industry analysis of key security issues that impact business-critical systems and applications. Delivering frequent and timely security and

[FD] [KIS-2021-03] ExpressionEngine <= 6.0.2 (Translate::save) PHP Code Injection Vulnerability

2021-03-15 Thread research
ExpressionEngine <= 6.0.2 (Translate::save) PHP Code Injection Vulnerability [-] Software Link: https://expressionengine.com/ [-] Affecte

[FD] [CVE-2021-28144] Authenticated Command Injection in D-Link DIR-3060 Web Interface

2021-03-11 Thread research
IoT Inspector Research Lab Security Advisory IOT-20210311-0 ~~~ title: Authenticated Command Injection in D-Link DIR-3060 Web Interface vendor/product: D-Link DIR-3060 (https

[FD] [KIS-2021-02] docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability

2021-02-19 Thread research
-- docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability -- [-] Software Link: https://docsify.js.org/ [-] Affected Versions: Version 4.11.6 and prior versions.

  1   2   3   4   >