Unix

IBM AIX 7.1 — CVE-2022-22473 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-22473 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 19 August 2022 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-22473, IBM Support Bulletin CVE: CVE-2022-22473 NVD summary: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative […]

Read more
IBM AIX 7.3 — CVE-2022-22442 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2022-22442 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 17 August 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2022-22442, IBM Support Bulletin CVE: CVE-2022-22442 NVD summary: "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. […]

Read more
IBM AIX 7.2 — CVE-2022-25256 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2022-25256 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 16 August 2022 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2022-25256, IBM PSIRT advisory page CVE: CVE-2022-25256 NVD summary: SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button […]

Read more
IBM AIX 7.3 — CVE-2022-35721 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2022-35721 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 16 August 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2022-35721, IBM Support Bulletin CVE: CVE-2022-35721 NVD summary: IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web […]

Read more
CHAT