Update to 2.40.7. This contains various security updates for which CVEs have apparently not yet been assigned.
Monthly Archives: February 2015
CVE-2014-6102
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX008, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly handle logout actions, which allows remote attackers to bypass intended Cognos BI Direct Integration access restrictions by leveraging an unattended workstation.
CVE-2014-6194
Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to read arbitrary files via a .. (dot dot) in a pathname.
CVE-2014-8023
Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users to bypass intended resource-access restrictions via a crafted tunnel-group parameter, aka Bug ID CSCtz48533.
GLSA 201502-13: Chromium: Multiple vulnerabilities
GLSA 201502-13: Chromium: Multiple vulnerabilities
Vuln: Oracle Java SE CVE-2014-2397 Remote Security Vulnerability
Oracle Java SE CVE-2014-2397 Remote Security Vulnerability
Vuln: Oracle Java SE CVE-2014-0449 Remote Security Vulnerability
Oracle Java SE CVE-2014-0449 Remote Security Vulnerability
Vuln: Linux Kernel cpio 'list_file()' Function Heap Based Buffer Overflow Vulnerability
Linux Kernel cpio ‘list_file()’ Function Heap Based Buffer Overflow Vulnerability
Vuln: Cpio Symlink Directory Traversal Vulnerability
Cpio Symlink Directory Traversal Vulnerability