Severity Rating: High

Software Affected
·         Apache Tomcat 10.0.0-M1 to 10.0.0-M5
·         Apache Tomcat 9.0.0.M1 to 9.0.35
·         Apache Tomcat 8.5.0 to 8.5.55

Overview
A vulnerability has been reported in Apache Tomcat which could allow an
attacker to cause a denial of service (DOS) condition on the target system.

Description
This vulnerability exists in Apache Tomcat when sufficient number of
requests are made on concurrent HTTP/2 connections. An attacker could
exploit this vulnerability by sending a specially crafted sequence of
HTTP/2 requests that could trigger high CPU usage for several seconds
resulting in the system to become unresponsive.

Successful exploitation of this vulnerability could allow the attacker to
cause a denial of service (DOS) condition on the target system.

Solution
Upgrade to latest Apache Tomcat version:

Vendor Information
Apache Tomcat

References
Apache Tomcat

RedHat

CVE Name
CVE-2020-11996

Severity Rating: Critical

Software Affected
PAN-OS 9.1 versions prior to PAN-OS 9.1.3
PAN-OS 9.0 versions prior to PAN-OS 9.0.9
PAN-OS 8.1 versions prior to PAN-OS 8.1.15
PAN-OS 8.0 (EOL)

Overview
A vulnerability has been reported in PAN-OS which could allow an
unauthenticated, remote attacker to gain access of protected resources.

Description
This vulnerability exists in Security Assertion Markup Language (SAML)
authentication in PAN-OS due to improper verification of cryptographic
signature. The vulnerability could be exploited when Security Assertion
Markup Language (SAML) authentication is enabled and the 'Validate Identity
Provider Certificate' option is disabled. An unauthenticated remote
attacker with network access to the vulnerable server could exploit this
vulnerability to gain access of protected resources within the network.

Successful exploitation of this vulnerability could allow the attacker to
conduct further attacks such as gaining administrative rights to compromise
the system.

The vulnerability cannot be exploited if;
·         SAML is not used for authentication.
·         'Validate Identity Provider Certificate' option is enabled
(checked) in the SAML Identity Provider Server Profile.

 Solution
Apply appropriate updates as mentioned in:


Vendor Information

Paloalto

Reference

Paloalto

Reddit


Tenable

CVE Name
(CVE-2020-2021)

Severity Rating: HIGH

Software Affected
·         VMware ESXi versions 7.0,  6.7,  6.5
·         VMware Workstation Pro / Player versions prior to 15.5.5
·         VMware Fusion Pro / Fusion versions prior to 11.5.5
·         VMware Cloud Foundation 4.x versions prior to 4.0.1
·         VMware Cloud Foundation 3.x versions prior to 3.10.0.1

Overview

Multiple vulnerabilities have been reported in VMware products which could
allow an attacker with local access to a virtual machine to execute
arbitrary code, cause denial of service conditions or access sensitive
information on a targeted hypervisor system.

Description

These vulnerabilities exist in VMware products due to use-after-free,
heap-overflow, off-by-one heap-overflow, out-of-bounds read, out-of-bounds
write, heap-overflow due to race condition and other errors in SVGA device,
Shader Functionality, EHCI controller, xHCI controller, xHCI USB
controller, EHCI USB controller, PVNVRAM and vmxnet3 components.

Successful exploitation of these vulnerabilities could allow an attacker
with local access to a virtual machine to execute arbitrary code, cause
denial of service conditions or access sensitive information on the
targeted hypervisor system.

Solution

Apply appropriate patches or workarounds as mentioned in VMware advisory.

Vendor Information
VMware

References
CyberSecurityHelp

CVE Name
CVE-2020-3962
CVE-2020-3963
CVE-2020-3964
CVE-2020-3965
CVE-2020-3966
CVE-2020-3967
CVE-2020-3968
CVE-2020-3969
CVE-2020-3970
CVE-2020-3971

Severity Rating: High

Software Affected
●      Internationalization (i18n) module for Drupal 7.x

Overview
A vulnerability has been reported in Drupal, which could be exploited by a
remote attacker to exploit  a Cross Site Scripting (XSS) vulnerability.

Description
The vulnerability exists in Drupal because a value in term translation
module is displayed without being escaped making a Cross Site Scripting
(XSS) possible. The attacker must have a role with permission "Edit terms
in" on a taxonomy vocabulary with i18n term translation enabled in order
to exploit the vulnerability.

Successful exploitation of this vulnerability could allow the attacker to
exploit the Cross Site Scripting (XSS) vulnerability to execute an
unauthorised script.

Solution
Apply appropriate patches as mentioned on Drupal website:

Vendor Information
Drupal

References
Drupal

Severity Rating: High

Software Affected
·         Red Hat JBoss Core Services 1 for RHEL 7 x86_64
·         Red Hat JBoss Core Services 1 for RHEL 6 x86_64
·         Red Hat JBoss Core Services 1 for RHEL 6 i386
·         Red Hat JBoss Core Services Text-Only Advisories x86_64

Overview
Multiple vulnerabilities have been reported in Red Hat JBoss which could be
exploited by an attacker to cause denial of service conditions or gain
access to sensitive information on a targeted system.

Description
1.    Use-After-Free Vulnerability (CVE-2019-0196)
This vulnerability exists in the mod_http2 module of Apache HTTP server due
to a use-after-free error on string comparison. A remote attacker could
exploit this vulnerability by sending a specially crafted request.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

2.    Memory Corruption Vulnerability (CVE-2019-0197)
This vulnerability exists in the mod_http2 module of Apache HTTP server due
to an error when HTTP/2 or H2Upgrade was enabled for http/https host. A
remote attacker could exploit this vulnerability by sending a specially
crafted request.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

3.    Denial of Service Vulnerability (CVE-2018-20843)
This vulnerability exists in libexpat in Expat due to improper restriction
of XML parser. An attacker could exploit this vulnerability by sending
crafted XML input which included XML names containing a large number of
colons            resulting in excessive consumption of RAM and CPU
resources.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

4.    Buffer Over-Read Vulnerability (CVE-2019-15903)
This vulnerability exists in libexpat in Expat due to improper restriction
of XML parser. An attacker could exploit this vulnerability by sending
crafted XML input leading to earlier processing from DTD parsing to
document parsing. This could lead to crashing of the target system.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

5.    Denial of Service Vulnerability (CVE-2019-19956)
This vulnerability exists in xmlParseBalancedChunkMemoryRecover in parser.c
in libxml2 due to a memory leak error related to newDoc->oldNs.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

6.    Denial of Service Vulnerability (CVE-2019- 20388)
This vulnerability exists in xmlSchemaPreRun in xmlschemas.c in libxml2 due
to a memory leak error.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

7.    Denial of Service Vulnerability (CVE-2020-7595)
This vulnerability exists in xmlStringLenDecodeEntities in parser.c in
libxml2 due to incorrect handling of XML files. This vulnerability could
lead to infinite loop in a certain end-of-file situation.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

8.    Information Disclosure Vulnerability (CVE-2020-1934)
This vulnerability exists in mod_proxy_ftp module of Apache HTTP server due
to the use of uninitialized memory variable while proxying to a malicious
FTP server.

Successful exploitation of this vulnerability could allow the attacker to
gain access to sensitive information.

9.    Denial of Service Vulnerability (CVE-2020-11080)
This vulnerability exists in nghttp2 due to improper neutralization of
input. An attacker could exploit this vulnerability by repeatedly
constructing a SETTINGS frame with a length of 14,400 bytes resulting in
excessive usage of RAM.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions.

Solution
Apply appropriate updates as mentioned in the vendor advisory

Vendor Information
Red Hat JBoss 

References
Red Hat

CVE Name
CVE-2019-0196
CVE-2019-0197
CVE-2019-19956
CVE-2019-20388
CVE-2020-7595
CVE-2018-20843
CVE-2019-15903
CVE-2020-1934
CVE-2020-11080

Severity Rating: High

Software Affected:
·         Magento Commerce 1 (Magento Enterprise Edition) 1.14.4.5 and earlier
·         Magento Open Source 1 (Magento Community Edition) 1.9.4.5 and earlier  

Overview
Multiple vulnerabilities have been reported in Magento 1 which could allow
an attacker with administrative privileges to execute arbitrary code or
gain access to sensitive information on a targeted system.

Description
1.    PHP Object Injection Vulnerability (CVE-2020-9664)
This vulnerability exists in Magento due to an error which allows PHP
Object Injection. PHP Object Injection can be exploited via crafted user
supplied input which is not sanitized properly before being passed to the
unserialize() PHP function.

Successful exploitation of this vulnerability could allow an attacker with
administrative privileges to execute arbitrary code on the targeted system.

2.    Stored Cross-Site Scripting Vulnerability (CVE-2020-9665)
This vulnerability exists in Magento due to an error which allows Stored
Cross-Site Scripting. Stored Cross-Site Scripting can be performed by
injecting a specially crafted script into a webpage of an affected system.

Successful exploitation of this vulnerability could allow an attacker with
administrative privileges to gain access to sensitive information on the
targeted system.

Solution:
Update to the latest versions as available at the following URL:

Note: Support for Magento Commerce 1.14 and Magento Open Source 1  is
ending in June 2020.  Users are advised to upgrade to Magento 2.x.  

Vendor Information
Adobe

References


IBM X-Force

CVE Name
CVE-2020-9664
CVE-2020-9665

Severity Rating: High     

Software Affected:
·         IBM Spectrum Protect Plus 10.1.0-10.1.5

Overview
Multiple vulnerabilities have been reported in IBM Spectrum Protect Plus
which could allow a remote attacker to cause a denial of service, or hijack
DNS sessions and execute arbitrary code on the targeted system.

Description

1.       Remote Code Execution Vulnerability (CVE-2020-4469)
This vulnerability exists in IBM Spectrum Protect Plus due to an incomplete
fix for CVE-2020-4211.A remote attacker could exploit this vulnerability by
using a specially crafted HTTP command on the system. Successful
exploitation of this vulnerability could execute arbitrary command on the
system.

2.       Denial of Service Vulnerability (CVE-2020-4471)
This vulnerability exists in IBM Spectrum Protect Plus due to improper
handling of HTTP command by the affected software. An unauthenticated
remote attacker could exploit this vulnerability by sending a specially
crafted HTTP command to remote server. Successful exploitation of this
vulnerability could cause a denial of service or hijack DNS sessions.

3.       Remote Code Execution Vulnerability (CVE-2020-4470)
This vulnerability exists in IBM Spectrum Protect Plus due to improper
handling of Administrative Console by the affected software. An
authenticated remote attacker could exploit this vulnerability to upload
the arbitrary files to the targeted remote server. Successful exploitation
of this vulnerability could execute arbitrary command on the system.

Solution
Apply appropriate security updates as mentioned in the IBM Advisory:

Vendor Information

References

CVE Name
CVE-2020-4469
CVE-2020-4470
CVE-2020-4471

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top