Unix

IBM AIX 7.3 — CVE-2023-42007 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2023-42007 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 24 January 2023 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2023-42007, IBM Support Bulletin CVE: CVE-2023-42007 NVD summary: IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the […]

Read more
IBM AIX 7.3 — CVE-2006-5005 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2006-5005 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 24 January 2023 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2006-5005, IBM Support Bulletin CVE: CVE-2006-5005 NVD summary: Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login. References: ftp://aix.software.ibm.com/aix/efixes/security/R […]

Read more
IBM AIX 7.1 — CVE-2022-34336 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-34336 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 21 January 2023 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-34336, IBM Support Bulletin CVE: CVE-2022-34336 NVD summary: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in […]

Read more
IBM AIX 7.3 — CVE-2023-29260 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2023-29260 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 19 January 2023 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2023-29260, IBM Support Bulletin CVE: CVE-2023-29260 NVD summary: IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from […]

Read more
CHAT