New User, Welcome!     Login

Next Page >>

managers

CA DSM gui_cm_ctrls ActiveX Control Vulnerability

web browser.


Mitigating Factors: For BrightStor ARCserve Backup for Laptops & 
Desktops, only the server installation is affected. Client 
installations are not affected. For CA Desktop Management Suite, 
Unicenter Desktop Management Bundle, Unicenter Asset Management, 
Unicenter Software Delivery and Unicenter Remote Control, only the 
Managers and DSM Explorers are affected. Scalability Servers and 
Agents are not affected.


Cisco Security Advisory: Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability

Communications Manager stores administrator accounts in the Cisco
Unified Communications Manager DC Directory service. If an attacker
obtains the DC Directory credentials and MLA is enabled, the attacker
can add an existing account to the Cisco Unified Communications
Manager super-user group. The attacker can then access the Cisco
Unified Communications Manager management interface with complete
administrative access. If MLA is not enabled, the attacker cannot
escalate their privileges; however, they can modify any user settings
in the directory.

The Cisco Unified Communications Manager 4.x IP Phone PAB

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Cisco Unified Communications Manager services are affected:

  * Certificate Trust List (CTL) Provider
  * Certificate Authority Proxy Function (CAPF)
  * Session Initiation Protocol (SIP)
  * Simple Network Management Protocol (SNMP) Trap

Cisco has released free software updates that address these
vulnerabilities. Workarounds that mitigate some of these
vulnerabilities are available.


Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Cisco Unified Communications Manager services are affected:

  * Certificate Trust List (CTL) Provider
  * Certificate Authority Proxy Function (CAPF)
  * Session Initiation Protocol (SIP)
  * Simple Network Management Protocol (SNMP) Trap

Cisco has released free software updates that address these
vulnerabilities. Workarounds that mitigate some of these
vulnerabilities are available.


Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified Communications Manager Denial
of Service Vulnerabilities

Advisory ID: cisco-sa-20100303-cucm

Revision 1.0


CA Multiple Products DSM ListCtrl ActiveX Control Buffer Overflow Vulnerability

browser. The vulnerability, CVE-2008-1472, is due to insufficient 
bounds checking on the ListCtrl AddColumn function.

Mitigating Factors: For BrightStor ARCserve Backup for Laptops & 
Desktops, only the server installation is affected. Client 
installations are not affected. For CA Desktop Management Suite, 
Unicenter Desktop Management Bundle, Unicenter Asset Management, 
Unicenter Software Delivery and Unicenter Remote Control, only the 
Managers and DSM Explorers are affected. Scalability Servers and 
Agents are not affected. 


Cisco Security Advisory: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified Communications Manager Session
Initiation Protocol Denial of Service Vulnerabilities

Advisory ID: cisco-sa-20080924-cucm

http://www.cisco.com/warp/public/707/cisco-sa-20080924-cucm.shtml


Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified Communications Manager Denial
of Service Vulnerabilities

Advisory ID: cisco-sa-20090826-cucm

Revision 1.0


CA20091008-01: Security Notice for CA Anti-Virus Engine

CA Internet Security Suite 2007 (v3)
CA Internet Security Suite 2008
CA Internet Security Suite Plus 2008
CA Internet Security Suite Plus 2009
CA Threat Manager for the Enterprise (formerly eTrust Integrated 
   Threat Management) r8
CA Threat Manager for the Enterprise (formerly eTrust Integrated 
   Threat Management) 8.1
CA Threat Manager Total Defense
CA Gateway Security r8.1
CA Protection Suites r2

Akamai Download Manager arbitrary file download & execution

------------------------------------------------------------------------
Akamai Download Manager arbitrary file download & execution
------------------------------------------------------------------------
Yorick Koster, April 2009

------------------------------------------------------------------------
Abstract
------------------------------------------------------------------------
Akamai's Download Manager allows attackers to download arbitrary
files onto a user's desktop. Using a so-called "blended

Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

|-------------------------------------+--------------+--------------|
|                                     | All versions | All versions |
| Crafted SSH Packet Vulnerability    | prior to A3  | prior to A2  |
|                                     | (2.1)        | (1.3)        |
|-------------------------------------+--------------+--------------|
| Crafted Simple Network Management   | All versions | All versions |
| Protocol version 2 (SNMPv2) Packet  | prior to A3  | prior to A2  |
| Vulnerability                       | (2.1)        | (1.3)        |
|-------------------------------------+--------------+--------------|
|                                     | All versions | All versions |
| Crafted SNMPv3 Packet Vulnerability | prior to A1  | prior to A2  |

Cisco Security Advisory: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified Communications Manager Session
Initiation Protocol Denial of Service Vulnerability

Advisory ID: cisco-sa-20090923-cm

Revision 1.0


Cisco Security Advisory: Cisco Security Manager Vulnerability

vulnerability.

Details
=======

Cisco Security Manager is an enterprise-class management application
that is designed to configure firewall, VPN, and intrusion prevention
security services on Cisco network and security devices. As part of
Cisco Security Manager installation, the Cisco IEV is installed by
default. The IEV is a Java-based application that allows users to
view and manage alerts for up to five sensors, including the ability

[security bulletin] HPSBMA02445 SSRT090058 rev.1 - HP Serviceguard Manager, Remote Execution of Arbitrary Code, Denial of Service (DoS)

END AFFECTED VERSIONS

HISTORY
Version:1 (rev.1) 28 July 2009 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For further information, contact normal HP Services support channel.

Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.

Cisco Security Advisory: CiscoWorks Common Services Arbitrary Code Execution Vulnerability

| Policy Manager  | 4.0.1,   | 3.0.5    |
| (QPM)           | and      |          |
|                 | 4.0.2    |          |
|-----------------+----------+----------|
| CiscoWorks LAN  | 2.5,     |          |
| Management      | 2.5.1,   | 3.0.3    |
| Solution (LMS)  | 2.6      |          |
|-----------------+----------+----------|
| CiscoWorks LAN  | 2.6      |          |
| Management      | Update   | 3.0.5    |
| Solution (LMS)  |          |          |

VMSA-2010-0012 VMware vCenter Update Manager fix for Jetty Web server addresses important security vulnerabilities

3. Problem Description

 a. VMware vCenter Update Manager Jetty Web server vulnerabilities

    VMware vCenter Update Manager is an automated patch management
    solution for VMware ESX hosts and Microsoft virtual machines. Update
    Manager embeds the Jetty Web server which is a third party
    component.

    The default version of the Jetty Web server in Update Manager is

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Agent

+---------------------------------------------------------------------

Summary
=======

The Management Center for Cisco Security Agents is affected by a
directory traversal vulnerability and a SQL injection vulnerability.
Successful exploitation of the directory traversal vulnerability may
allow an authenticated attacker to view and download arbitrary files
from the server hosting the Management Center. Successful
exploitation of the SQL injection vulnerability may allow an

Hopeless comments regarding the pointless "HP System Management Homepage (SMH) Unspecified XSS"

=====================================================================================
Hopeless comments regarding the pointless 
"HP System Management Homepage (SMH) Unspecified XSS"

August 25, 2008

=====================================================================================
[Overview]

Since HP does not provide technical details in its security bulletins, it is really

Cisco Security Advisory: Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities

vulnerabilities.

Details
=======

ANM is a network management application that manages Cisco ACE modules
or appliances. ANM is installed on customer provided servers with a Red
Hat Enterprise Linux operating system. The ACE Device Manager provides
a browser-based interface for configuring and managing a single ACE
appliance. The ACE Device Manager resides in flash memory on the ACE
appliance. Multiple vulnerabilities exist in ANM and one in the ACE

Cisco Security Advisory: Default Passwords in the Application Velocity System

Vulnerable Products
+------------------

This vulnerability affects the Cisco AVS 3110, 3120, 3180, and 3180A
Management Station appliances that are running software versions prior
to AVS 5.1.0. Administrators can determine the software version of the
AVS appliances by logging in to the Management Station web-based user
interface or from the command-line interface (CLI) of the appliance
operating system.


[G-SEC 46-2009] Computer Associates multiple products arbritary code execution

CA Internet Security Suite 2007 (v3)
CA Internet Security Suite 2008
CA Internet Security Suite Plus 2008
CA Internet Security Suite Plus 2009
CA Threat Manager for the Enterprise (formerly eTrust Integrated 
   Threat Management) r8
CA Threat Manager for the Enterprise (formerly eTrust Integrated 
   Threat Management) 8.1
CA Threat Manager Total Defense
CA Gateway Security r8.1
CA Protection Suites r2

CA20090806-02: Security Notice for Unicenter Asset Portfolio Management, Unicenter Desktop and Server Management, Unicenter Patch Management

CA20090806-02: Security Notice for Unicenter Asset Portfolio
Management, Unicenter Desktop and Server Management, Unicenter
Patch Management

Issued: August 6, 2009

CA's technical support is alerting customers to a security risk with
Unicenter Asset Portfolio Management, Unicenter Desktop and Server
Management, and Unicenter Patch Management. The release of Tomcat as
included with the products is potentially susceptible to a cross-site

[security bulletin] HPSBMA02492 SSRT100079 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02029444
Version: 1

HPSBMA02492 SSRT100079 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2010-04-20
Last Updated: 2010-04-20

VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues

- -----------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2009-0017
Synopsis:          VMware vCenter, ESX patch and vCenter Lab Manager
                   releases address cross-site scripting issues
Issue date:        2009-12-15
Updated on:        2009-12-15 (initial release of advisory)
CVE numbers:       CVE-2009-3731
- -----------------------------------------------------------------------

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified Communications Manager Denial
                         of Service and Authentication Bypass
                         Vulnerabilities

Advisory ID: cisco-sa-20080625-cucm

Revision 1.0

Cisco Security Advisory: Vulnerability in Cisco WebEx Meeting Manager ActiveX Control

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Vulnerability in Cisco WebEx Meeting Manager
                         ActiveX Control

Advisory ID: cisco-sa-20080814-webex

Revision 1.0


[security bulletin] HPSBMA02504 SSRT090220 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Cross Site Scripting (XSS)

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02000727
Version: 1

HPSBMA02504 SSRT090220 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Cross Site Scripting (XSS)

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2010-02-03
Last Updated: 2010-02-03

Cisco Security Advisory: Transport Layer Security Renegotiation Vulnerability

|----------------------------+-------------------------------|
| Cisco Unified Contact      | CSCtd05790                    |
| Center Express             |                               |
|----------------------------+-------------------------------|
| Cisco Unified Contact      | CSCtd05755                    |
| Center Management Portal   |                               |
|----------------------------+-------------------------------|
| Cisco Unified Contact      | CSCtd05790                    |
| Center Products            |                               |
|----------------------------+-------------------------------|
| Cisco Unified Department   | CSCtd05733                    |

[security bulletin] HPSBMA02438 SSRT090092 rev.1 - HP ProLiant DL/ML 100 Series G5/G6 Servers with ProLiant Onboard Administrator Powered by LO100i, Remote Denial of Service (DoS)

A potential vulnerability has been identified with certain HP ProLiant DL/ML 100 Series G5/G6 Servers with ProLiant Onboard Administrator Powered by LO100i. The vulnerability could be exploited remotely to create a Denial of Service (DoS). The HP ProLiant Onboard Administrator Powered by LO100i was formerly known as HP Lights Out 100.

References: CVE-2009-1426

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
Any of the following ProLiant DL/ML100 G5/G6-Series servers with Lights-Out 100 Remote Management Firmware Version 3.07 or earlier:

HP ProLiant DL120 G5 Server series
HP ProLiant DL160 G5 Server series
HP ProLiant DL160 G6 Server series
HP ProLiant DL160 G5p Server series

POC - Sun Java System Acccess Manager & Identity Manager Users Enumeration

============================================================
 Sun Java System Acccess Manager & Identity Manager Users Enumeration
============================================================

 Affected Software: Sun Java System Access Server, OpenSSo
                               Sun Java System Identity Manager

 Author: Marco Mella - marco[ dot ]mella[at]aboutsecurity[dot]net
 More information, Advisory and POC URL: http://www.aboutsecurity.net


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!