New User, Welcome!     Login

Next Page >>

business information

[Onapsis Security Advisory 2011-003] SAP WebAS ITS Mobile Start Service Multiple Vulnerabilities

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2011-014] SAP WebAS Remote Denial of Service

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.

About Onapsis

[Onapsis Security Advisory 2011-015] SAP WebAS webrfc Cross-Site Scripting

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.

About Onapsis

[Onapsis Security Advisory 2011-016] SAP WebAS Malicious SAP Shortcut Generation

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.

About Onapsis

[Onapsis Security Advisory 2012-01] Oracle JD Edwards JDENET Arbitrary File Write

1. Impact on Business
=====================

By exploiting this vulnerability, a remote unauthenticated attacker might be able to access or modify all the business information processed by the
ERP system.
This would result in the total compromise of the ERP infrastructure.

2. Advisory Information
=======================

[Onapsis Security Advisory 2012-02] Oracle JD Edwards Security Kernel Remote Password Disclosure

1. Impact on Business
=====================

By exploiting this vulnerability, a remote unauthenticated attacker might be able to access or modify all the business information processed by the
ERP system.
This would result in the total compromise of the ERP infrastructure.

2. Advisory Information
=======================

[Onapsis Security Advisory 2012-03] Oracle JD Edwards SawKernel Arbitrary File Read

With that objective in mind, a special unit – the Onapsis Research Labs – has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2010-006] SAP J2EE Web Services Navigator Cross-Site Scripting

security vulnerabilities in these platforms.

The outcome of this advanced and cutting-edge research is continuously
provided to the Onapsis Consulting and Development teams, improving
the quality of our solutions and enabling our customers to be
protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared
with the general security and professional community,  encouraging the
sharing of information and increasing the common knowledge in this field.


[Onapsis Security Advisory 2010-010] Oracle Virtual Server Agent Local Privilege Escalation

With that objective in mind, a special unit - the Onapsis Research Labs - has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2011-007] Oracle JD Edwards JDENET Kernel Shutdown

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



XCon 2010 XFocus Information Security Conference Call for Paper

      - Vista / Windows 
      - Web 2.0
      - 3G/4G network
      - Mobile Handset (Symbian / IPhone / Android / Windows Mobile )
      - Banks & Financial institutes
      - Business Information System
      - Virtualization 
      - New bug digging

   --- Application security
      - Web application vulnerability research

The XCon2010 is coming

      - Vista / Windows 
      - Web 2.0
      - 3G/4G network
      - Mobile Handset (Symbian / IPhone / Android / Windows Mobile )
      - Banks & Financial institutes
      - Business Information System
      - Virtualization 
      - New bug digging

   --- Application security
      - Web application vulnerability research

NSFOCUS SA2009-02 : IBM DB2 JDBC Applet Server Remote DoS Vulnerability

Description:
==========

IBM DB2 is a large-scale business relational database system oriented to E-commerce,
business information, content management, customer relation management and
other applications. IBM DB2 operates on AIX, HP-UX, Linux, Solaris and Windows.

There exists a vulnerability in function jdbcReadString() of IBM DB2 JDBC
Applet Server. When converting UNICODE to ANSI string, the function uses the
length field from the packet directly without validating the actual string

[Onapsis Security Advisory 2010-001] SAP WebAS Integrated ITS Remote Command Execution

With that objective in mind, a special unit – the Onapsis Research Labs – has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2011-004] SAP WebAS ITS Mobile Test Service Multiple Vulnerabilities

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



xcon2009 is coming

      - Vista
      - Web 2.0
      - 3G/4G network
      - Mobile Handset (Symbian / IPhone / Android / Windows Mobile )
      - Banks & financial institutes
      - Business Information System
      - Virtualzation 
      - New vulnerability discovering

   --- Application security
      - Web application vulnerability research

[Onapsis Security Advisory 2010-009] Oracle Virtual Server Agent Remote Command Execution

With that objective in mind, a special unit - the Onapsis Research Labs - has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2011-001] SAP Management Console Unauthenticated Service Restart

With that objective in mind, a special unit – the Onapsis Research Labs – has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2010-007] SAP Management Console Multiple Denial of Service

With that objective in mind, a special unit - the Onapsis Research Labs - has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2011-010] Oracle JD Edwards JDENET Remote Logging Deactivation

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2011-002] SAP Management Console Information Disclosure

With that objective in mind, a special unit – the Onapsis Research Labs – has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



XCon 2011 XFocus Information Security Conference Call for Paper

   -3G/4G/WINMAX,TD-SCDMA
   - Mobile Handset (IPhone / Android / Windows Mobile 7 )
   -Web2.0  
   -SNS Application
   - Banks & Financial institutes
   - Business Information System
   - Virtualization

--- Application security
   - Web application vulnerability research
   - Application reverse engineering and related automated tools

[Onapsis Security Advisory 2011-011] Oracle JD Edwards JDENET Buffer Overflow

?

?1. Impact on Business
=====================

By exploiting this vulnerability, a remote unauthenticated attacker might be able to   access or modify all the business information processed by the
ERP system.
This would result in the total compromise of the ERP infrastructure.

- -- Risk Level: High


[Onapsis Security Advisory 2011-012] Oracle JD Edwards JDENET Firewall Bypass

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2012-06] Oracle JD Edwards JDENET Large Packets Denial of Service

With that objective in mind, a special unit – the Onapsis Research Labs – has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2010-004] SAP J2EE Authentication Phishing Vector

The outcome of this advanced and cutting-edge research is continuously
provided to the Onapsis Consulting and Development teams, improving the
quality
of our solutions and enabling our customers to be protected from the
latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared
with the general security and professional community, encouraging the
sharing of
information and increasing the common knowledge in this field.

[Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection

The outcome of this advanced and cutting-edge research is continuously
provided to the Onapsis Consulting and Development teams, improving the
quality
of our solutions and enabling our customers to be protected from the
latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared
with the general security and professional community, encouraging the
sharing of
information and increasing the common knowledge in this field.

[Onapsis Security Advisory 2011-013] Oracle JD Edwards JDENET USRBROADCAST Denial of Service

With that objective in mind, a special unit ? the Onapsis Research Labs ? has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2012-08] Oracle JD Edwards Security Kernel Information Disclosure

With that objective in mind, a special unit – the Onapsis Research Labs – has been developed since the creation of the company. The experts involved
in this special team lead the public research trends in this matter, having discovered and published many of the public security vulnerabilities in
these platforms.

The outcome of this advanced and cutting-edge research is continuously provided to the Onapsis Consulting and Development teams, improving the quality
of our solutions and enabling our customers to be protected from the latest risks to their critical business information.

Furthermore, the results of this research projects are usually shared with the general security and professional community, encouraging the sharing of
information and increasing the common knowledge in this field.



[Onapsis Security Advisory 2011-009] Oracle JD Edwards JDENET SawKernel Remote Password Disclosure

?1. Impact on Business
=====================

By exploiting this vulnerability, a remote unauthenticated attacker might be able to   obtain valid access credentials and access or modify all the
business information processed by the ERP system.
This would result in the total compromise of the ERP infrastructure.

- -- Risk Level: High



Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!