Show filters
391 Total Results
Displaying 21-30 of 391
Sort by:
Attacker Value
Unknown
CVE-2024-8689
Disclosure Date: September 11, 2024 (last updated September 12, 2024)
A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.
0
Attacker Value
Unknown
CVE-2024-40681
Disclosure Date: September 07, 2024 (last updated October 31, 2024)
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.
0
Attacker Value
Unknown
CVE-2024-40680
Disclosure Date: September 07, 2024 (last updated October 31, 2024)
IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.
0
Attacker Value
Unknown
CVE-2024-8105
Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown
CVE-2024-23321
Disclosure Date: July 22, 2024 (last updated February 14, 2025)
For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions.
An attacker, possessing regular user privileges or listed in the IP whitelist, could potentially acquire the administrator's account and password through specific interfaces. Such an action would grant them full control over RocketMQ, provided they have access to the broker IP address list.
To mitigate these security threats, it is strongly advised that users upgrade to version 5.3.0 or newer. Additionally, we recommend users to use RocketMQ ACL 2.0 instead of the original RocketMQ ACL when upgrading to version Apache RocketMQ 5.3.0.
0
Attacker Value
Unknown
CVE-2024-39743
Disclosure Date: July 08, 2024 (last updated August 08, 2024)
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 297172.
0
Attacker Value
Unknown
CVE-2024-39742
Disclosure Date: July 08, 2024 (last updated August 08, 2024)
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
0
Attacker Value
Unknown
CVE-2024-35156
Disclosure Date: June 28, 2024 (last updated August 22, 2024)
IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292766.
0
Attacker Value
Unknown
CVE-2024-35116
Disclosure Date: June 28, 2024 (last updated August 22, 2024)
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. IBM X-Force ID: 290335.
0
Attacker Value
Unknown
CVE-2024-35155
Disclosure Date: June 28, 2024 (last updated August 02, 2024)
IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292765.
0