An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers before 2.1.0 allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.
Monthly Archives: July 2016
CVE-2016-5787
General Electric (GE) Digital Proficy HMI/SCADA – CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.
CVE-2016-5790
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote attackers to bypass authentication and restart the software via unspecified vectors.
CVE-2016-5797
Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.
CVE-2016-5804
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
CVE-2016-5807
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, via a direct request.
Microsoft Wins! Govt Can't Force Tech Companies to Hand Over Data Stored Overseas
Especially after the Snowden revelations of global mass surveillance by US intelligence agencies at home and abroad, various countries demanded tech companies including Google, Apple, and Microsoft to set-up and maintain their servers in respective countries in order to keep their citizen data within boundaries.
The US government has powers to comply US-based tech companies with the court
![]()
[ERPSCAN-16-019] SAP NetWeaver Enqueue Server – DoS vulnerability
Posted by ERPScan inc on Jul 15
Application: SAP NetWeaver Enqueue Server
Versions Affected: SAP NetWeaver Enqueue Server 7.4
Vendor URL: http://SAP.com
Bug: denial of service
Sent: 04.12.2015
Reported: 05.12.2015
Vendor response: 05.12.2015
Date of Public Advisory: 12.04.2016
Reference: SAP Security Note 2258784
Author: Vahagn Vardanyan (ERPScan)
Description
1. ADVISORY INFORMATION
Title: SAP NetWeaver Enqueue Server – DoS vulnerability
Advisory ID:…
[ERPSCAN-16-020] SAP NetWeaver AS JAVA UDDI component – XXE vulnerability
Posted by ERPScan inc on Jul 15
Application: SAP NetWeaver AS JAVA
Versions Affected: SAP NetWeaver AS JAVA 7.4
Vendor URL: http://SAP.com
Bug: XXE
Sent: 04.12.2015
Reported: 05.12.2015
Vendor response: 05.12.2015
Date of Public Advisory: 12.04.2016
Reference: SAP Security Note 2254389
Author: Vahagn Vardanyan (ERPScan)
Description
1. ADVISORY INFORMATION
Title: SAP NetWeaver AS JAVA UDDI component – XXE vulnerability
Advisory ID: [ERPSCAN-16-020]
Risk:…
[ERPSCAN-16-021] SAP xMII – Reflected XSS vulnerability
Posted by ERPScan inc on Jul 15
Application: SAP xMII
Versions Affected: SAP xMII 15
Vendor URL: http://SAP.com
Bugs: XSS
Sent: 04.12.2015
Reported: 05.12.2015
Vendor response: 05.12.2015
Date of Public Advisory: 12.04.2016
Reference: SAP Security Note 2201295
Author: Nursultan Abubakirov (ERPScan) , Vahagn Vardanyan (ERPScan)
Description
1. ADVISORY INFORMATION
Title: SAP xMII – Reflected XSS vulnerability
Advisory ID: [ERPSCAN-16-021]
Risk: medium
Advisory…
