KL-001-2017-003 : Trendmicro InterScan Remote Root Access Vulnerability

2017-02-15 Thread KoreLogic Disclosures
KL-001-2017-003 : Trendmicro InterScan Remote Root Access Vulnerability Title: Trendmicro InterScan Remote Root Access Vulnerability Advisory ID: KL-001-2017-003 Publication Date: 2017.02.15 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2017-003.txt 1. Vulnerability

KL-001-2017-001 : Trendmicro InterScan Arbitrary File Write

2017-02-15 Thread KoreLogic Disclosures
KL-001-2017-001 : Trendmicro InterScan Arbitrary File Write Title: Trendmicro InterScan Arbitrary File Write Advisory ID: KL-001-2017-001 Publication Date: 2017.02.15 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2017-001.txt 1. Vulnerability Details Affected

Cisco Security Advisory: Cisco UCS Director Privilege Escalation Vulnerability

2017-02-15 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco UCS Director Privilege Escalation Vulnerability Advisory ID: cisco-sa-20170215-ucs Revision 1.0 For Public Release 2017 February 15 16:00 UTC (GMT

CVE-2017-5585: SQL injection in OpenText Documentum Content Server 7.3 (PostgreSQL builds only)

2017-02-15 Thread Andrey B. Panfilov
CVE Identifier: CVE-2017-5585 Vendor: OpenText Affected products: OpenText Documentum Content Server 7.3 (PostgreSQL builds only) Researcher: Andrey B. Panfilov Severity Rating: CVSS v3 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Fix: not available Description: Previously announced

Advisory X41-2017-002: Multiple Vulnerabilities in ytnef

2017-02-15 Thread X41 D-Sec GmbH Advisories
X41 D-Sec GmbH Security Advisory: X41-2017-002 Multiple Vulnerabilities in ytnef = Overview Severity Rating: High Confirmed Affected Versions: 1.9 and earlier Confirmed Patched Versions: 1.9.1 Vendor: Yerase Vendor URL: https://github.com/Yeraze/ytnef

CVE-2017-5586: Remote code execution in OpenText Documentum D2

2017-02-15 Thread Andrey B. Panfilov
CVE Identifier: CVE-2017-5586 Vendor: OpenText Affected products: Documentum D2 version 4.x Researcher: Andrey B. Panfilov Severity Rating: CVSS v3 Base Score: 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) Description: Document D2 contains vulnerable BeanShell (bsh) and Apache Commons libraries and