The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.
Monthly Archives: August 2015
CVE-2015-3221
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.
CVE-2015-3239
Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.
CVE-2015-4037
The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.
CVE-2015-4173
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender with firmware before 7.5.1.2 and 8.x before 8.0.0.3 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
Bugtraq: [security bulletin] HPSBGN03399 rev.1 – HP BSM Connector (BSMC), Remote Unauthorized Modification, Disclosure of Information
[security bulletin] HPSBGN03399 rev.1 – HP BSM Connector (BSMC), Remote Unauthorized Modification, Disclosure of Information
Bugtraq: [security bulletin] HPSBGN03405 rev.1 – HP Integration Adaptor, Remote Unauthorized Modification, Disclosure of Information
[security bulletin] HPSBGN03405 rev.1 – HP Integration Adaptor, Remote Unauthorized Modification, Disclosure of Information
Bugtraq: CVE-2015-6535: Stored XSS in YouTube Embed (WordPress plugin) allows admins to compromise super admins
CVE-2015-6535: Stored XSS in YouTube Embed (WordPress plugin) allows admins to compromise super admins
Bugtraq: [security bulletin] HPSBGN03411 rev.1 – HP Operations Agent Virtual Appliance, Remote Unauthorized Disclosure of Information
[security bulletin] HPSBGN03411 rev.1 – HP Operations Agent Virtual Appliance, Remote Unauthorized Disclosure of Information
CVE-2015-5409
Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.