IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
Monthly Archives: December 2016
CVE-2016-3033 (appscan_source)
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVE-2016-3044
The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.
CVE-2016-3047 (filenet_workplace)
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2016-3055 (filenet_workplace)
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVE-2016-9751 (piwigo)
Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CVE-2016-9752 (serendipity)
In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status code.
Gooligan steals more than 1m Google accounts
Your Google Play, Gmail, Google Photos, Google Docs, G Suite, Google Drive, and more apps aren’t secure anymore. Gooligan, a new malware infects your Android devices.
The post Gooligan steals more than 1m Google accounts appeared first on Avira Blog.
Advent calendar raffle – the terms and conditions
Here you can find the terms and conditions of our Avira Advent calendar.
The post Advent calendar raffle – the terms and conditions appeared first on Avira Blog.
Sweeten your winter time – with our Advent calendar raffle!
With our Advent calendar you can win great prizes from Avira – even license keys!
The post Sweeten your winter time – with our Advent calendar raffle! appeared first on Avira Blog.