Unix

IBM AIX 7.1 — CVE-2022-25256 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-25256 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 13 February 2023 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-25256, IBM PSIRT advisory page CVE: CVE-2022-25256 NVD summary: SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button […]

Read more
IBM AIX 7.1 — CVE-2022-40750 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-40750 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 13 February 2023 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-40750, IBM Support Bulletin CVE: CVE-2022-40750 NVD summary: IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web […]

Read more
IBM AIX 7.3 — CVE-2020-4771 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2020-4771 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 11 February 2023 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2020-4771, IBM Support Bulletin CVE: CVE-2020-4771 NVD summary: IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication […]

Read more
IBM AIX 7.3 — CVE-2010-2594 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2010-2594 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 11 February 2023 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2010-2594, IBM PSIRT advisory page CVE: CVE-2010-2594 NVD summary: Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in InterSect Alliance Snare Agent 3.2.3 and earlier on Solaris, Snare Agent […]

Read more
IBM AIX 7.3 — CVE-2021-29737 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2021-29737 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 11 February 2023 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2021-29737, IBM Support Bulletin CVE: CVE-2021-29737 NVD summary: IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force […]

Read more
IBM AIX 7.1 — CVE-2022-36772 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-36772 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 10 February 2023 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-36772, IBM Support Bulletin CVE: CVE-2022-36772 NVD summary: IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user. References: […]

Read more
CHAT