This updates includes a rebase from tomcat 7.0.72 up to 7.0.73 which resolves multiple CVEs:
* #1397495 – CVE-2016-6816 CVE-2016-8735 tomcat: various flaws
This updates includes a rebase from tomcat 7.0.72 up to 7.0.73 which resolves multiple CVEs:
* #1397495 – CVE-2016-6816 CVE-2016-8735 tomcat: various flaws
This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolves multiple CVEs:
* #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws
This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolves multiple CVEs:
* #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws
This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolves multiple CVEs:
* #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended access restrictions via modified request parameters.
Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.
This module enables you to manage cron jobs.
The module allows users with the permission “Administer elysia cron” to execute arbitrary PHP code via cron.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission “Administer elysia cron”. This permission is not marked as “restricted”.
Drupal core is not affected. If you do not use the contributed Elysia Cron module, there is nothing you need to do.
Revoke the permission “Administer elysia cron” for untrusted users.
Elysia cron 7.x-2.4 and up will indicate that the permission is restricted.
Also see the Elysia Cron project page.
The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.
Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.
Follow the Drupal Security Team on Twitter at https://twitter.com/drupalsecurity
Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authenticated users to inject arbitrary web script or HTML via crafted fields in a URL.