Calenderweek 35

Addressing Splunk Enterprise Vulnerabilities: Patching Cross-Site Scripting, Denial of Service, and More

Splunk Enterprise harbors multiple vulnerabilities, including Cross-site Scripting (XSS), Denial of Service (DoS), Remote Code Execution, Privilege Escalation, and Path Traversal, with severity ratings ranging from 6.3 (Medium) to 8.8 (High). Addressing these concerns, Splunk has issued security advisories detailing patches for these vulnerabilities. CVE-2023-40592: Reflected Cross-Site Scripting (XSS) This vulnerability permits attackers to execute …

Addressing Splunk Enterprise Vulnerabilities: Patching Cross-Site Scripting, Denial of Service, and More Read More »

VMware Vulnerability Report: SAML Token Signature Bypass and Mitigation Measures

A vulnerability affecting VMware involving a SAML token signature bypass has been reported, potentially allowing threat actors to execute VMware Guest operations. Assigned the CVE ID CVE-2023-20900, this vulnerability is classified with a severity rating of 7.5 (High). VMware tools encompass a suite of modules and services designed to enhance various functionalities within VMware products. …

VMware Vulnerability Report: SAML Token Signature Bypass and Mitigation Measures Read More »

ArubaOS-Switch Vulnerabilities: Risks and Remediation Measures

ArubaOS-Switch Switches have been found to contain multiple vulnerabilities, including Stored Cross-site Scripting (Stored XSS), Denial of Service (DoS), and Memory Corruption issues. Aruba, the owner of ArubaOS-Switch and a subsidiary of Hewlett Packard Enterprise, has taken steps to address these vulnerabilities and has released a security advisory. ArubaOS-Switch allows centralized network management and is …

ArubaOS-Switch Vulnerabilities: Risks and Remediation Measures Read More »

Scroll to Top