ENISA EUVD · EUVD-2020-0387Known-exploited evidence recordedIn jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Official EUVD record ↗BSI · German · WID-SEC-2025-1459Dell Data Protection Advisor: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um weitere nicht näher spezifizierte Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2024-3191Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2023-0239Red Hat JBoss Enterprise Application Platform: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um beliebigen Programmcode auszuführen, ein Cross-Site-Scritping-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2023-0063Juniper Junos Space: Mehrere SchwachstellenEin Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.
Official advisory ↗BSI · German · WID-SEC-2024-1872IBM QRadar SIEM: Mehrere SchwachstellenEin entfernter anonymer oder authentifizierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, einen Denial-of-Service-Zustand auszulösen und einen Cross-Site-Scripting-Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2022-1347jQuery: Mehrere Schwachstellen ermöglichen Cross-Site ScriptingEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20200506Security Bulletin 06 May 2020The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 06 May 2020, published on 6 May 2020. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMord?id=CVE-2019-10099
Référence CVE CVE-2019-11358
https://www.cve.org/CVERecord?id=CVE-2019-11358
Référence CVE CVE-2019-14893
https://www.cve.org/CVERecord?id=CVE-2019-14893
Référence CVE CVE-2019-16869
https://www.cve.org/CVERecord?id=CVE-2019-16869
Référence CVE CVE-2019-20444
https://www.cve.org/CVERecord?id=CVE-2019-20444
Référence CVE CVE-2019-20445
https://www.cve.org/CVERecord?id=CVE-2019-20445
Référence CVE CVE-2019-8331
https://www.cve.org/CVERecord?id=CVE-2019-8331
Référence CVE CVE-2020-10683
https://www.cve.org/CVERecord?id=CVE-2020-10683
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-11988
https://www.cve.org/CVERecord?id=CVE-2020-11988
Référence CVE CVE-2020-13955
https://www.cve.org/CVERecord?id=CVE-2020-13955
Référence CVE CVE-2020-26555
https://www.cve.org/CVERecord?id=CVE-2020-26555
Référence CVE CVE-2020-26945
https://www.cve.org/CVERecord?id=CVE-2020-26945
Référence CVE CVE-2020-7656
https://www.cve.org/CVERecord?id=CVE-2020-7656
Référence CVE CVE-2020-9480
https://www.cve.org/CVERecord?id=CVE-2020-9480
Référence CVE CVE-2020-9492
https://www.cve.org/CVERecord?id=CVE-2020-9492
Référence CVE CVE-2021-21290
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMwareERecord?id=CVE-2018-25032
Référence CVE CVE-2018-9996
https://www.cve.org/CVERecord?id=CVE-2018-9996
Référence CVE CVE-2019-13232
https://www.cve.org/CVERecord?id=CVE-2019-13232
Référence CVE CVE-2019-25013
https://www.cve.org/CVERecord?id=CVE-2019-25013
Référence CVE CVE-2019-2708
https://www.cve.org/CVERecord?id=CVE-2019-2708
Référence CVE CVE-2019-9076
https://www.cve.org/CVERecord?id=CVE-2019-9076
Référence CVE CVE-2020-10029
https://www.cve.org/CVERecord?id=CVE-2020-10029
Référence CVE CVE-2020-10543
https://www.cve.org/CVERecord?id=CVE-2020-10543
Référence CVE CVE-2020-10878
https://www.cve.org/CVERecord?id=CVE-2020-10878
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-12723
https://www.cve.org/CVERecord?id=CVE-2020-12723
Référence CVE CVE-2020-12762
https://www.cve.org/CVERecord?id=CVE-2020-12762
Référence CVE CVE-2020-16599
https://www.cve.org/CVERecord?id=CVE-2020-16599
Référence CVE CVE-2020-1752
https://www.cve.org/CVERecord?id=CVE-2020-1752
Référence CVE CVE-2020-19726
https://www.cve.org/CVERecord?id=CVE-2020-19726
Référence CVE CVE-2020-22916
https://www.cve.org/CVERecord?id=CVE-2020-22916
Référence CVE CVE-2020-27618
https://www.cve.org/CVERecord?id=CVE-2020-27618
Référence CVE CVE-2020-29562
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0855Multiples vulnérabilités dans les produits Juniper Networksrg/CVERecord?id=CVE-2015-3253
Référence CVE CVE-2015-5377
https://www.cve.org/CVERecord?id=CVE-2015-5377
Référence CVE CVE-2018-17244
https://www.cve.org/CVERecord?id=CVE-2018-17244
Référence CVE CVE-2018-17247
https://www.cve.org/CVERecord?id=CVE-2018-17247
Référence CVE CVE-2018-3823
https://www.cve.org/CVERecord?id=CVE-2018-3823
Référence CVE CVE-2018-3824
https://www.cve.org/CVERecord?id=CVE-2018-3824
Référence CVE CVE-2018-3826
https://www.cve.org/CVERecord?id=CVE-2018-3826
Référence CVE CVE-2018-3831
https://www.cve.org/CVERecord?id=CVE-2018-3831
Référence CVE CVE-2019-12900
https://www.cve.org/CVERecord?id=CVE-2019-12900
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2021-22146
https://www.cve.org/CVERecord?id=CVE-2021-22146
Référence CVE CVE-2021-3903
https://www.cve.org/CVERecord?id=CVE-2021-3903
Référence CVE CVE-2021-40153
https://www.cve.org/CVERecord?id=CVE-2021-40153
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-41043
https://www.cve.org/CVERecord?id=CVE-2021-41043
Référence CVE CVE-2021-41072
https://www.cve.org/CVERecord?id=CVE-2021-41072
Référence CVE CVE-2021-42550
https://www.cve.org/CVERecord?id=CVE-2021-42550
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0693Multiples vulnérabilités dans VMware Tanzupport-content-notification/-/external/content/SecurityAdvisories/0/36035
Bulletin de sécurité VMware 36036 du 14 août 2025
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36036
Bulletin de sécurité VMware 36037 du 14 août 2025
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36037
Bulletin de sécurité VMware 36038 du 14 août 2025
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36038
Référence CVE CVE-2019-12900
https://www.cve.org/CVERecord?id=CVE-2019-12900
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2021-20197
https://www.cve.org/CVERecord?id=CVE-2021-20197
Référence CVE CVE-2021-32256
https://www.cve.org/CVERecord?id=CVE-2021-32256
Référence CVE CVE-2021-3572
https://www.cve.org/CVERecord?id=CVE-2021-3572
Référence CVE CVE-2021-3826
https://www.cve.org/CVERecord?id=CVE-2021-3826
Référence CVE CVE-2021-3927
https://www.cve.org/CVERecord?id=CVE-2021-3927
Référence CVE CVE-2021-3928
https://www.cve.org/CVERecord?id=CVE-2021-3928
Référence CVE CVE-2021-3968
https://www.cve.org/CVERecord?id=CVE-2021-3968
Référence CVE CVE-2021-3973
https://www.cve.org/CVERecord?id=CVE-2021-39
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0524Multiples vulnérabilités dans VMware Tanzu/CVERecord?id=CVE-2019-8396
Référence CVE CVE-2019-8397
https://www.cve.org/CVERecord?id=CVE-2019-8397
Référence CVE CVE-2019-8398
https://www.cve.org/CVERecord?id=CVE-2019-8398
Référence CVE CVE-2019-9151
https://www.cve.org/CVERecord?id=CVE-2019-9151
Référence CVE CVE-2019-9152
https://www.cve.org/CVERecord?id=CVE-2019-9152
Référence CVE CVE-2020-10809
https://www.cve.org/CVERecord?id=CVE-2020-10809
Référence CVE CVE-2020-10810
https://www.cve.org/CVERecord?id=CVE-2020-10810
Référence CVE CVE-2020-10811
https://www.cve.org/CVERecord?id=CVE-2020-10811
Référence CVE CVE-2020-10812
https://www.cve.org/CVERecord?id=CVE-2020-10812
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-18232
https://www.cve.org/CVERecord?id=CVE-2020-18232
Référence CVE CVE-2020-18494
https://www.cve.org/CVERecord?id=CVE-2020-18494
Référence CVE CVE-2021-26220
https://www.cve.org/CVERecord?id=CVE-2021-26220
Référence CVE CVE-2021-26221
https://www.cve.org/CVERecord?id=CVE-2021-26221
Référence CVE CVE-2021-26222
https://www.cve.org/CVERecord?id=CVE-2021-26222
Référence CVE CVE-2021-30485
https://www.cve.org/CVERecord?id=CVE-2021-30485
Référence CVE CVE-2021-31229
https://www.cve.org/CVERecord?id=CVE-2021-31229
Référence CVE CVE-2021-31347
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0422Multiples vulnérabilités dans IBM QRadar SIEMà 7.5.0 UP12
QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP12
Résumé
De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité IBM 7233394 du 14 mai 2025
https://www.ibm.com/support/pages/node/7233394
Référence CVE CVE-2019-12900
https://www.cve.org/CVERecord?id=CVE-2019-12900
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-13955
https://www.cve.org/CVERecord?id=CVE-2020-13955
Référence CVE CVE-2022-34169
https://www.cve.org/CVERecord?id=CVE-2022-34169
Référence CVE CVE-2022-39135
https://www.cve.org/CVERecord?id=CVE-2022-39135
Référence CVE CVE-2022-41678
https://www.cve.org/CVERecord?id=CVE-2022-41678
Référence CVE CVE-2022-42003
https://www.cve.org/CVERecord?id=CVE-2022-42003
Référence CVE CVE-2022-42004
https://www.cve.org/CVERecord?id=CVE-2022-42004
Référence CVE CVE-2022-49043
https://www.cve.org/CVERecord?id=CVE-2022-49043
Référence CVE CVE-2023-0286
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0401Multiples vulnérabilités dans Juniper Networks Secure AnalyticsSe référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Juniper Networks JSA98556 du 13 mai 2025
https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP11-IF03
Référence CVE CVE-2016-2193
https://www.cve.org/CVERecord?id=CVE-2016-2193
Référence CVE CVE-2017-9047
https://www.cve.org/CVERecord?id=CVE-2017-9047
Référence CVE CVE-2018-12699
https://www.cve.org/CVERecord?id=CVE-2018-12699
Référence CVE CVE-2019-12900
https://www.cve.org/CVERecord?id=CVE-2019-12900
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-21469
https://www.cve.org/CVERecord?id=CVE-2020-21469
Référence CVE CVE-2021-37533
https://www.cve.org/CVERecord?id=CVE-2021-37533
Référence CVE CVE-2022-48773
https://www.cve.org/CVERecord?id=CVE-2022-48773
Référence CVE CVE-2022-49043
https://www.cve.org/CVERecord?id=CVE-2022-49043
Référence CVE CVE-2023-2454
https://www.cve.org/CVERecord?id=CVE-2023-2454
Référence CVE CVE-2023-2455
https://www.cve.org/CVERecord?id=CVE-2023-2455
Référence CVE CVE-2023-37920
https://www.cve.org/CVERecord?id=CVE-2023-37920
Référence CVE CVE-2023-52492
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0370Multiples vulnérabilités dans les produits IBM.cve.org/CVERecord?id=CVE-2016-0714
Référence CVE CVE-2016-5018
https://www.cve.org/CVERecord?id=CVE-2016-5018
Référence CVE CVE-2016-5388
https://www.cve.org/CVERecord?id=CVE-2016-5388
Référence CVE CVE-2016-6796
https://www.cve.org/CVERecord?id=CVE-2016-6796
Référence CVE CVE-2016-6797
https://www.cve.org/CVERecord?id=CVE-2016-6797
Référence CVE CVE-2016-6816
https://www.cve.org/CVERecord?id=CVE-2016-6816
Référence CVE CVE-2016-8735
https://www.cve.org/CVERecord?id=CVE-2016-8735
Référence CVE CVE-2017-5647
https://www.cve.org/CVERecord?id=CVE-2017-5647
Référence CVE CVE-2017-9047
https://www.cve.org/CVERecord?id=CVE-2017-9047
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-8022
https://www.cve.org/CVERecord?id=CVE-2020-8022
Référence CVE CVE-2022-49043
https://www.cve.org/CVERecord?id=CVE-2022-49043
Référence CVE CVE-2023-52922
https://www.cve.org/CVERecord?id=CVE-2023-52922
Référence CVE CVE-2024-11218
https://www.cve.org/CVERecord?id=CVE-2024-11218
Référence CVE CVE-2024-40695
https://www.cve.org/CVERecord?id=CVE-2024-40695
Référence CVE CVE-2024-50302
https://www.cve.org/CVERecord?id=CVE-2024-50302
Référence CVE CVE-2024-51466
https://www.cve.org/CVERecord?id=CVE-2024-51466
Référence CVE CVE-2024-53197
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0214Multiples vulnérabilités dans les produits IBMeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité IBM 7185257 du 10 mars 2025
https://www.ibm.com/support/pages/node/7185257
Bulletin de sécurité IBM 7185353 du 11 mars 2025
https://www.ibm.com/support/pages/node/7185353
Bulletin de sécurité IBM 7185675 du 13 mars 2025
https://www.ibm.com/support/pages/node/7185675
Bulletin de sécurité IBM 7185937 du 14 mars 2025
https://www.ibm.com/support/pages/node/7185937
Bulletin de sécurité IBM 7185938 du 14 mars 2025
https://www.ibm.com/support/pages/node/7185938
Référence CVE CVE-2019-12900
https://www.cve.org/CVERecord?id=CVE-2019-12900
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2021-32803
https://www.cve.org/CVERecord?id=CVE-2021-32803
Référence CVE CVE-2021-32804
https://www.cve.org/CVERecord?id=CVE-2021-32804
Référence CVE CVE-2022-1365
https://www.cve.org/CVERecord?id=CVE-2022-1365
Référence CVE CVE-2022-1471
https://www.cve.org/CVERecord?id=CVE-2022-1471
Référence CVE CVE-2022-24302
https://www.cve.org/CVERecord?id=CVE-2022-24302
Référence CVE CVE-2022-25857
https://www.cve.org/CVERecord?id=CVE-2022-25857
Référence CVE CVE-2022-35737
https://www.cve.org/CVERecord?id=CVE-2022-35737
Référence CVE CVE-2022-38900
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-1103Multiples vulnérabilités dans les produits IBMERecord?id=CVE-2019-14973
Référence CVE CVE-2019-17006
https://www.cve.org/CVERecord?id=CVE-2019-17006
Référence CVE CVE-2019-17007
https://www.cve.org/CVERecord?id=CVE-2019-17007
Référence CVE CVE-2019-17023
https://www.cve.org/CVERecord?id=CVE-2019-17023
Référence CVE CVE-2019-17546
https://www.cve.org/CVERecord?id=CVE-2019-17546
Référence CVE CVE-2019-6128
https://www.cve.org/CVERecord?id=CVE-2019-6128
Référence CVE CVE-2019-7317
https://www.cve.org/CVERecord?id=CVE-2019-7317
Référence CVE CVE-2019-8331
https://www.cve.org/CVERecord?id=CVE-2019-8331
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-12400
https://www.cve.org/CVERecord?id=CVE-2020-12400
Référence CVE CVE-2020-12401
https://www.cve.org/CVERecord?id=CVE-2020-12401
Référence CVE CVE-2020-12403
https://www.cve.org/CVERecord?id=CVE-2020-12403
Référence CVE CVE-2020-15110
https://www.cve.org/CVERecord?id=CVE-2020-15110
Référence CVE CVE-2020-18768
https://www.cve.org/CVERecord?id=CVE-2020-18768
Référence CVE CVE-2020-19131
https://www.cve.org/CVERecord?id=CVE-2020-19131
Référence CVE CVE-2020-19144
https://www.cve.org/CVERecord?id=CVE-2020-19144
Référence CVE CVE-2020-19189
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0741Multiples vulnérabilités dans Juniper Secure AnalyticsSA86686 du 30 septembre 2024
https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP9-IF02
Référence CVE CVE-2018-20060
https://www.cve.org/CVERecord?id=CVE-2018-20060
Référence CVE CVE-2018-25091
https://www.cve.org/CVERecord?id=CVE-2018-25091
Référence CVE CVE-2019-11358
https://www.cve.org/CVERecord?id=CVE-2019-11358
Référence CVE CVE-2019-14865
https://www.cve.org/CVERecord?id=CVE-2019-14865
Référence CVE CVE-2019-25162
https://www.cve.org/CVERecord?id=CVE-2019-25162
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-13936
https://www.cve.org/CVERecord?id=CVE-2020-13936
Référence CVE CVE-2020-15778
https://www.cve.org/CVERecord?id=CVE-2020-15778
Référence CVE CVE-2020-23064
https://www.cve.org/CVERecord?id=CVE-2020-23064
Référence CVE CVE-2020-26555
https://www.cve.org/CVERecord?id=CVE-2020-26555
Référence CVE CVE-2020-36777
https://www.cve.org/CVERecord?id=CVE-2020-36777
Référence CVE CVE-2021-33198
https://www.cve.org/CVERecord?id=CVE-2021-33198
Référence CVE CVE-2021-34558
https://www.cve.org/CVERecord?id=CVE-2021-34558
Référence CVE CVE-2021-40153
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0737Multiples vulnérabilités dans Moxa OnCell 3120-LTE-1 SeriesDe multiples vulnérabilités ont été découvertes dans Moxa OnCell 3120-LTE-1 Series. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS).
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0579Multiples vulnérabilités dans les produits IBMécurité IBM 7159934 du 10 juillet 2024
https://www.ibm.com/support/pages/node/7159934
Bulletin de sécurité IBM 7160013 du 11 juillet 2024
https://www.ibm.com/support/pages/node/7160013
Bulletin de sécurité IBM 7160014 du 11 juillet 2024
https://www.ibm.com/support/pages/node/7160014
Bulletin de sécurité IBM 7160017 du 11 juillet 2024
https://www.ibm.com/support/pages/node/7160017
Bulletin de sécurité IBM 7160134 du 12 juillet 2024
https://www.ibm.com/support/pages/node/7160134
Référence CVE CVE-2019-11358
https://www.cve.org/CVERecord?id=CVE-2019-11358
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-13936
https://www.cve.org/CVERecord?id=CVE-2020-13936
Référence CVE CVE-2020-15778
https://www.cve.org/CVERecord?id=CVE-2020-15778
Référence CVE CVE-2020-23064
https://www.cve.org/CVERecord?id=CVE-2020-23064
Référence CVE CVE-2021-40153
https://www.cve.org/CVERecord?id=CVE-2021-40153
Référence CVE CVE-2021-41072
https://www.cve.org/CVERecord?id=CVE-2021-41072
Référence CVE CVE-2022-3287
https://www.cve.org/CVERecord?id=CVE-2022-3287
Référence CVE CVE-2023-25193
https://www.cve.org/CVERecord?id=CVE-2023-25193
Référence CVE CVE-2023-29483
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0508Multiples vulnérabilités dans les produits MoxaDe multiples vulnérabilités ont été découvertes dans les produits Moxa. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0459Multiples vulnérabilités dans les produits IBMd?id=CVE-2019-19203
Référence CVE CVE-2019-19204
https://www.cve.org/CVERecord?id=CVE-2019-19204
Référence CVE CVE-2019-20330
https://www.cve.org/CVERecord?id=CVE-2019-20330
Référence CVE CVE-2020-10650
https://www.cve.org/CVERecord?id=CVE-2020-10650
Référence CVE CVE-2020-10672
https://www.cve.org/CVERecord?id=CVE-2020-10672
Référence CVE CVE-2020-10673
https://www.cve.org/CVERecord?id=CVE-2020-10673
Référence CVE CVE-2020-10968
https://www.cve.org/CVERecord?id=CVE-2020-10968
Référence CVE CVE-2020-10969
https://www.cve.org/CVERecord?id=CVE-2020-10969
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-11111
https://www.cve.org/CVERecord?id=CVE-2020-11111
Référence CVE CVE-2020-11112
https://www.cve.org/CVERecord?id=CVE-2020-11112
Référence CVE CVE-2020-11113
https://www.cve.org/CVERecord?id=CVE-2020-11113
Référence CVE CVE-2020-11619
https://www.cve.org/CVERecord?id=CVE-2020-11619
Référence CVE CVE-2020-11620
https://www.cve.org/CVERecord?id=CVE-2020-11620
Référence CVE CVE-2020-13956
https://www.cve.org/CVERecord?id=CVE-2020-13956
Référence CVE CVE-2020-14060
https://www.cve.org/CVERecord?id=CVE-2020-14060
Référence CVE CVE-2020-14061
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0907Multiples vulnérabilités dans Moxa PT-G503De multiples vulnérabilités ont été découvertes dans Moxa PT-G503.
Certaines d'entre elles permettent à un attaquant de provoquer un
contournement de la politique de sécurité, une atteinte à l'intégrité
des données et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0357Multiples vulnérabilités dans IBM CognosRecord?id=CVE-2017-7656
Référence CVE CVE-2017-7657
https://www.cve.org/CVERecord?id=CVE-2017-7657
Référence CVE CVE-2017-7658
https://www.cve.org/CVERecord?id=CVE-2017-7658
Référence CVE CVE-2018-12536
https://www.cve.org/CVERecord?id=CVE-2018-12536
Référence CVE CVE-2018-12545
https://www.cve.org/CVERecord?id=CVE-2018-12545
Référence CVE CVE-2019-10241
https://www.cve.org/CVERecord?id=CVE-2019-10241
Référence CVE CVE-2019-10247
https://www.cve.org/CVERecord?id=CVE-2019-10247
Référence CVE CVE-2019-11358
https://www.cve.org/CVERecord?id=CVE-2019-11358
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-27218
https://www.cve.org/CVERecord?id=CVE-2020-27218
Référence CVE CVE-2020-27223
https://www.cve.org/CVERecord?id=CVE-2020-27223
Référence CVE CVE-2021-28165
https://www.cve.org/CVERecord?id=CVE-2021-28165
Référence CVE CVE-2021-28169
https://www.cve.org/CVERecord?id=CVE-2021-28169
Référence CVE CVE-2021-29425
https://www.cve.org/CVERecord?id=CVE-2021-29425
Référence CVE CVE-2021-34428
https://www.cve.org/CVERecord?id=CVE-2021-34428
Référence CVE CVE-2021-37533
https://www.cve.org/CVERecord?id=CVE-2021-37533
Référence CVE CVE-2022-2047
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0250Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été corrigées dans les produits IBM . Elles permettent à un attaquant de provoquer
un contournement de la politique de sécurité, une injection de code
indirecte à distance (XSS), une élévation de privilèges et une atteinte
à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0219Multiples vulnérabilités dans IBM Sterling B2B IntegratorDe multiples vulnérabilités ont été découvertes dans IBM Sterling B2B
Integrator. Certaines d'entre elles permettent à un attaquant de
provoquer un contournement de la politique de sécurité, une atteinte à
l'intégrité des données et une atteinte à la confidentialité des
données.
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0208Multiples vulnérabilités dans NessusDe multiples vulnérabilités ont été découvertes dans les produits Tenable . Elles permettent à un attaquant de
provoquer une exécution de code arbitraire à distance, un déni de
service à distance et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0190Multiples vulnérabilités dans Tenable NessusDe multiples vulnérabilités ont été découvertes dans Tenable Nessus.
Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire à distance et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-928Multiples vulnérabilités dans les produits IBMERecord?id=CVE-2019-10202
Référence CVE CVE-2019-10744
https://www.cve.org/CVERecord?id=CVE-2019-10744
Référence CVE CVE-2019-11358
https://www.cve.org/CVERecord?id=CVE-2019-11358
Référence CVE CVE-2019-16935
https://www.cve.org/CVERecord?id=CVE-2019-16935
Référence CVE CVE-2019-18348
https://www.cve.org/CVERecord?id=CVE-2019-18348
Référence CVE CVE-2019-9636
https://www.cve.org/CVERecord?id=CVE-2019-9636
Référence CVE CVE-2019-9740
https://www.cve.org/CVERecord?id=CVE-2019-9740
Référence CVE CVE-2019-9947
https://www.cve.org/CVERecord?id=CVE-2019-9947
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-13936
https://www.cve.org/CVERecord?id=CVE-2020-13936
Référence CVE CVE-2020-15523
https://www.cve.org/CVERecord?id=CVE-2020-15523
Référence CVE CVE-2020-26116
https://www.cve.org/CVERecord?id=CVE-2020-26116
Référence CVE CVE-2020-27619
https://www.cve.org/CVERecord?id=CVE-2020-27619
Référence CVE CVE-2020-28469
https://www.cve.org/CVERecord?id=CVE-2020-28469
Référence CVE CVE-2020-4051
https://www.cve.org/CVERecord?id=CVE-2020-4051
Référence CVE CVE-2020-7598
https://www.cve.org/CVERecord?id=CVE-2020-7598
Référence CVE CVE-2020-7656
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-924Multiples vulnérabilités dans IBM QRadaretin de sécurité IBM 6830017 du 17 octobre 2022
https://www.ibm.com/support/pages/node/6830017
Référence CVE CVE-2018-16487
https://www.cve.org/CVERecord?id=CVE-2018-16487
Référence CVE CVE-2018-25031
https://www.cve.org/CVERecord?id=CVE-2018-25031
Référence CVE CVE-2018-3721
https://www.cve.org/CVERecord?id=CVE-2018-3721
Référence CVE CVE-2019-1010266
https://www.cve.org/CVERecord?id=CVE-2019-1010266
Référence CVE CVE-2019-10744
https://www.cve.org/CVERecord?id=CVE-2019-10744
Référence CVE CVE-2019-11358
https://www.cve.org/CVERecord?id=CVE-2019-11358
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-28469
https://www.cve.org/CVERecord?id=CVE-2020-28469
Référence CVE CVE-2020-7598
https://www.cve.org/CVERecord?id=CVE-2020-7598
Référence CVE CVE-2020-7788
https://www.cve.org/CVERecord?id=CVE-2020-7788
Référence CVE CVE-2020-8203
https://www.cve.org/CVERecord?id=CVE-2020-8203
Référence CVE CVE-2021-22959
https://www.cve.org/CVERecord?id=CVE-2021-22959
Référence CVE CVE-2021-22960
https://www.cve.org/CVERecord?id=CVE-2021-22960
Référence CVE CVE-2021-23337
https://www.cve.org/CVERecord?id=CVE-2021-23337
Référence CVE CVE-2021-23346
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-266Multiples vulnérabilités dans IBM WebSphere Service Registry and RepositoryDe multiples vulnérabilités ont été découvertes dans IBM WebSphere
Service Registry and Repository. Certaines d'entre elles permettent à un
attaquant de provoquer une exécution de code arbitraire à distance, un
déni de service à distance et un contournement de la politique de
sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-056Multiples vulnérabilités dans Oracle WebLogic Serverdécouvertes dans Oracle WebLogic
Server. Certaines d'entre elles permettent à un attaquant de provoquer
une exécution de code arbitraire à distance, un déni de service à
distance et une atteinte à l'intégrité des données.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des
correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Oracle cpujan2022.html du 18 janvier 2022
https://www.oracle.com/security-alerts/cpujan2022.html#AppendixFMW
Référence CVE CVE-2018-1324
https://www.cve.org/CVERecord?id=CVE-2018-1324
Référence CVE CVE-2019-10219
https://www.cve.org/CVERecord?id=CVE-2019-10219
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-13956
https://www.cve.org/CVERecord?id=CVE-2020-13956
Référence CVE CVE-2020-2934
https://www.cve.org/CVERecord?id=CVE-2020-2934
Référence CVE CVE-2020-5258
https://www.cve.org/CVERecord?id=CVE-2020-5258
Référence CVE CVE-2021-27568
https://www.cve.org/CVERecord?id=CVE-2021-27568
Référence CVE CVE-2021-29425
https://www.cve.org/CVERecord?id=CVE-2021-29425
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2022-21252
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-943Multiples vulnérabilités dans les produits IBMd?id=CVE-2019-10172
Référence CVE CVE-2019-14892
https://www.cve.org/CVERecord?id=CVE-2019-14892
Référence CVE CVE-2019-14893
https://www.cve.org/CVERecord?id=CVE-2019-14893
Référence CVE CVE-2020-10672
https://www.cve.org/CVERecord?id=CVE-2020-10672
Référence CVE CVE-2020-10673
https://www.cve.org/CVERecord?id=CVE-2020-10673
Référence CVE CVE-2020-10683
https://www.cve.org/CVERecord?id=CVE-2020-10683
Référence CVE CVE-2020-10968
https://www.cve.org/CVERecord?id=CVE-2020-10968
Référence CVE CVE-2020-10969
https://www.cve.org/CVERecord?id=CVE-2020-10969
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-11111
https://www.cve.org/CVERecord?id=CVE-2020-11111
Référence CVE CVE-2020-11112
https://www.cve.org/CVERecord?id=CVE-2020-11112
Référence CVE CVE-2020-11113
https://www.cve.org/CVERecord?id=CVE-2020-11113
Référence CVE CVE-2020-11619
https://www.cve.org/CVERecord?id=CVE-2020-11619
Référence CVE CVE-2020-11620
https://www.cve.org/CVERecord?id=CVE-2020-11620
Référence CVE CVE-2020-13956
https://www.cve.org/CVERecord?id=CVE-2020-13956
Référence CVE CVE-2020-14060
https://www.cve.org/CVERecord?id=CVE-2020-14060
Référence CVE CVE-2020-14061
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-770Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquant de provoquer un déni
de service, un contournement de la politique de sécurité et une atteinte
à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-430Multiples vulnérabilités dans Tenable LCEDe multiples vulnérabilités ont été découvertes dans Tenable LCE. Elles
permettent à un attaquant de provoquer une exécution de code arbitraire,
un déni de service à distance et un contournement de la politique de
sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-295Multiples vulnérabilités dans Oracle DatabaseDe multiples vulnérabilités ont été découvertes dans Oracle Database.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, un déni de service à distance
et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-196Multiples vulnérabilités dans MoodleDe multiples vulnérabilités ont été découvertes dans Moodle. Certaines
d'entre elles permettent à un attaquant de provoquer un problème de
sécurité non spécifié par l'éditeur, un contournement de la politique de
sécurité et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-130Multiples vulnérabilités dans Tenable Nessus Network MonitorDe multiples vulnérabilités ont été découvertes dans Tenable Nessus
Network Monitor. Elles permettent à un attaquant de provoquer un
contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-775Multiples vulnérabilités dans ZimbraDe multiples vulnérabilités ont été découvertes dans Zimbra. Elles
permettent à un attaquant de provoquer une exécution de code arbitraire
à distance.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-662Multiples vulnérabilités dans Oracle Database ServerDe multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un attaquant de provoquer
une exécution de code arbitraire à distance, un déni de service à
distance et une atteinte à l'intégrité des données. Cet avis ne liste
pas les CVE pour lesquelles l'éditeur considère qu'elles ne sont pas
exploitables dans le contexte d'exécution du produit.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-549Multiples vulnérabilités dans les produits SAPSAPUI5_JAVA) version 7.50
Résumé
De multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire à distance et un contournement de la politique de sécurité.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des
correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité SAP du 08 septembre 2020
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
Référence CVE CVE-2020-11022
https://www.cve.org/CVERecord?id=CVE-2020-11022
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-6207
https://www.cve.org/CVERecord?id=CVE-2020-6207
Référence CVE CVE-2020-6275
https://www.cve.org/CVERecord?id=CVE-2020-6275
Référence CVE CVE-2020-6282
https://www.cve.org/CVERecord?id=CVE-2020-6282
Référence CVE CVE-2020-6283
https://www.cve.org/CVERecord?id=CVE-2020-6283
Référence CVE CVE-2020-6288
https://www.cve.org/CVERecord?id=CVE-2020-6288
Référence CVE CVE-2020-6296
https://www.cve.org/CVERecord?id=CVE-2020-6296
Référence CVE CVE-2020-6302
https://www.cve.org/CVERecord?id=CVE-2020-6302
Référence CVE CVE-2020-6311
https://www.cve.org/CVERecord?id=CVE-2020-6311
R
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-495Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire à distance et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-335Multiples vulnérabilités dans Joomla!De multiples vulnérabilités ont été découvertes dans Joomla!. Elles
permettent à un attaquant de provoquer un contournement de la politique
de sécurité et une injection de code indirecte à distance (XSS).
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-310Multiples vulnérabilités dans DrupalDe multiples vulnérabilités ont été découvertes dans Drupal. Elles
permettent à un attaquant de provoquer un contournement de la politique
de sécurité et une injection de code indirecte à distance (XSS).
Official advisory ↗NBSZ-NKI · Hungarian · cve-2020-11023CVE-2020-11023Közepes
Official advisory ↗JVN iPedia · Japanese · JVNDB-2020-005056jQuery におけるクロスサイトスクリプティングの脆弱性jQuery には、クロスサイトスクリプティングの脆弱性が存在します。
Official advisory ↗NCSC-NL · Dutch · NCSC-2024-0417Kwetsbaarheden verholpen in Oracle Fusion MiddlewareEen kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipuleren van data
- Uitvoer van willekeurige code (Administratorrechten)
- Toegang tot gevoelige gegevens
Omdat deze kwetsbaarheden zich bevinden in diverse Middleware producten, is niet uit te sluiten dat applicaties, draaiende op platformen ondersteund door deze middleware ook kwetsbaar zijn, danwel gevoelig voor misbruik van deze kwetsbaarheden.
Official advisory ↗