ENISA EUVD · EUVD-2024-3049Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2026-1229Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2025-0647Splunk Splunk Enterprise: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen preiszugeben, Daten zu manipulieren, Code auszuführen, einen Denial-of-Service-Zustand zu verursachen und weitere, nicht spezifizierte Auswirkungen zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2025-0516Camunda: Mehrere Schwachstellen ermöglichen Cross-Site ScriptingEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Camunda ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2025-0043IBM QRadar SIEM (Log Source Management App): Mehrere SchwachstellenEin entfernter anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um einen Cross-Site-Scripting-Angriff zu starten, beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und Sicherheitsmaßnahmen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2024-3542Red Hat OpenShift: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Dateien zu manipulieren, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu erzeugen, beliebigen Code auszuführen und einen Cross-Site-Scripting-Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2024-3338Red Hat OpenShift: Mehrere SchwachstelleEin entfernter, anonymer Angreifer kann mehrere Schwachstelle in Red Hat OpenShift ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen und beliebigen Code auszuführen.
Official advisory ↗BSI · German · WID-SEC-2026-1498Pega Platform: Schwachstelle ermöglicht Cross-Site ScriptingEin entfernter, anonymer Angreifer kann eine Schwachstelle in Pega Platform ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0264Dell EMC Unity: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell EMC Unity ausnutzen, um beliebigen Code mit Root-Rechten auszuführen, Cross-Site-Scripting-Angriffe durchzuführen und Sicherheitsmaßnahmen zu umgehen.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20241016Security Bulletin 16 Oct 2024The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 16 Oct 2024, published on 16 October 2024. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0500Multiples vulnérabilités dans VMware Tanzud?id=CVE-2024-29133
Référence CVE CVE-2024-29857
https://www.cve.org/CVERecord?id=CVE-2024-29857
Référence CVE CVE-2024-30171
https://www.cve.org/CVERecord?id=CVE-2024-30171
Référence CVE CVE-2024-34447
https://www.cve.org/CVERecord?id=CVE-2024-34447
Référence CVE CVE-2024-36114
https://www.cve.org/CVERecord?id=CVE-2024-36114
Référence CVE CVE-2024-37890
https://www.cve.org/CVERecord?id=CVE-2024-37890
Référence CVE CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
Référence CVE CVE-2024-47554
https://www.cve.org/CVERecord?id=CVE-2024-47554
Référence CVE CVE-2024-47561
https://www.cve.org/CVERecord?id=CVE-2024-47561
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2024-48910
https://www.cve.org/CVERecord?id=CVE-2024-48910
Référence CVE CVE-2024-53382
https://www.cve.org/CVERecord?id=CVE-2024-53382
Référence CVE CVE-2024-56373
https://www.cve.org/CVERecord?id=CVE-2024-56373
Référence CVE CVE-2024-57083
https://www.cve.org/CVERecord?id=CVE-2024-57083
Référence CVE CVE-2024-57699
https://www.cve.org/CVERecord?id=CVE-2024-57699
Référence CVE CVE-2024-6485
https://www.cve.org/CVERecord?id=CVE-2024-6485
Référence CVE CVE-2024-7254
https://www.cve.org/CVERecord?id=CVE-2024-7254
Référence CVE CVE-2024-8184
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0479Multiples vulnérabilités dans les produits Atlassian.com/browse/JSWSERVER-26765
Référence CVE CVE-2021-0341
https://www.cve.org/CVERecord?id=CVE-2021-0341
Référence CVE CVE-2021-31597
https://www.cve.org/CVERecord?id=CVE-2021-31597
Référence CVE CVE-2022-1471
https://www.cve.org/CVERecord?id=CVE-2022-1471
Référence CVE CVE-2023-1370
https://www.cve.org/CVERecord?id=CVE-2023-1370
Référence CVE CVE-2023-3635
https://www.cve.org/CVERecord?id=CVE-2023-3635
Référence CVE CVE-2023-48631
https://www.cve.org/CVERecord?id=CVE-2023-48631
Référence CVE CVE-2024-29371
https://www.cve.org/CVERecord?id=CVE-2024-29371
Référence CVE CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2025-48734
https://www.cve.org/CVERecord?id=CVE-2025-48734
Référence CVE CVE-2025-66020
https://www.cve.org/CVERecord?id=CVE-2025-66020
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-23745
https://www.cve.org/CVERecord?id=CVE-2026-23745
Référence CVE CVE-2026-23950
https://www.cve.org/CVERecord?id=CVE-2026-23950
Référence CVE CVE-2026-24842
https://www.cve.org/CVERecord?id=CVE-2026-24842
Référence CVE CVE-2026-25547
https://www.cve.org/CVERecord?id=CVE-2026-25547
Référence CVE CVE-2026-25639
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0249Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-40635
Référence CVE CVE-2024-41909
https://www.cve.org/CVERecord?id=CVE-2024-41909
Référence CVE CVE-2024-43398
https://www.cve.org/CVERecord?id=CVE-2024-43398
Référence CVE CVE-2024-45296
https://www.cve.org/CVERecord?id=CVE-2024-45296
Référence CVE CVE-2024-45336
https://www.cve.org/CVERecord?id=CVE-2024-45336
Référence CVE CVE-2024-45338
https://www.cve.org/CVERecord?id=CVE-2024-45338
Référence CVE CVE-2024-45341
https://www.cve.org/CVERecord?id=CVE-2024-45341
Référence CVE CVE-2024-47072
https://www.cve.org/CVERecord?id=CVE-2024-47072
Référence CVE CVE-2024-47535
https://www.cve.org/CVERecord?id=CVE-2024-47535
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2024-48910
https://www.cve.org/CVERecord?id=CVE-2024-48910
Référence CVE CVE-2024-50264
https://www.cve.org/CVERecord?id=CVE-2024-50264
Référence CVE CVE-2024-50302
https://www.cve.org/CVERecord?id=CVE-2024-50302
Référence CVE CVE-2024-51479
https://www.cve.org/CVERecord?id=CVE-2024-51479
Référence CVE CVE-2024-51744
https://www.cve.org/CVERecord?id=CVE-2024-51744
Référence CVE CVE-2024-52798
https://www.cve.org/CVERecord?id=CVE-2024-52798
Référence CVE CVE-2024-53113
https://www.cve.org/CVERecord?id=CVE-2024-53113
Référence CVE CVE-2024-55565
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0563Multiples vulnérabilités dans les produits Splunkd?id=CVE-2024-29857
Référence CVE CVE-2024-32002
https://www.cve.org/CVERecord?id=CVE-2024-32002
Référence CVE CVE-2024-34064
https://www.cve.org/CVERecord?id=CVE-2024-34064
Référence CVE CVE-2024-38999
https://www.cve.org/CVERecord?id=CVE-2024-38999
Référence CVE CVE-2024-39338
https://www.cve.org/CVERecord?id=CVE-2024-39338
Référence CVE CVE-2024-45230
https://www.cve.org/CVERecord?id=CVE-2024-45230
Référence CVE CVE-2024-45337
https://www.cve.org/CVERecord?id=CVE-2024-45337
Référence CVE CVE-2024-45338
https://www.cve.org/CVERecord?id=CVE-2024-45338
Référence CVE CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2024-48949
https://www.cve.org/CVERecord?id=CVE-2024-48949
Référence CVE CVE-2024-49767
https://www.cve.org/CVERecord?id=CVE-2024-49767
Référence CVE CVE-2024-52616
https://www.cve.org/CVERecord?id=CVE-2024-52616
Référence CVE CVE-2024-52804
https://www.cve.org/CVERecord?id=CVE-2024-52804
Référence CVE CVE-2024-6345
https://www.cve.org/CVERecord?id=CVE-2024-6345
Référence CVE CVE-2024-7264
https://www.cve.org/CVERecord?id=CVE-2024-7264
Référence CVE CVE-2024-8096
https://www.cve.org/CVERecord?id=CVE-2024-8096
Référence CVE CVE-2024-9143
https://www.cve.org/CVERecord?id=CVE-202
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0245Multiples vulnérabilités dans les produits SplunkDe multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0243Multiples vulnérabilités dans VMware Tanzu GemfireDe multiples vulnérabilités ont été découvertes dans VMware Tanzu Gemfire. Elles permettent à un attaquant de provoquer un déni de service à distance, une injection de code indirecte à distance (XSS) et un problème de sécurité non spécifié par l'éditeur.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0210Multiples vulnérabilités dans VMware TanzuDe multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0045Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-43788
Référence CVE CVE-2024-43796
https://www.cve.org/CVERecord?id=CVE-2024-43796
Référence CVE CVE-2024-43799
https://www.cve.org/CVERecord?id=CVE-2024-43799
Référence CVE CVE-2024-43800
https://www.cve.org/CVERecord?id=CVE-2024-43800
Référence CVE CVE-2024-45296
https://www.cve.org/CVERecord?id=CVE-2024-45296
Référence CVE CVE-2024-45590
https://www.cve.org/CVERecord?id=CVE-2024-45590
Référence CVE CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
Référence CVE CVE-2024-47068
https://www.cve.org/CVERecord?id=CVE-2024-47068
Référence CVE CVE-2024-47764
https://www.cve.org/CVERecord?id=CVE-2024-47764
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2024-48948
https://www.cve.org/CVERecord?id=CVE-2024-48948
Référence CVE CVE-2024-48949
https://www.cve.org/CVERecord?id=CVE-2024-48949
Référence CVE CVE-2024-52798
https://www.cve.org/CVERecord?id=CVE-2024-52798
Référence CVE CVE-2024-55565
https://www.cve.org/CVERecord?id=CVE-2024-55565
Gestion détaillée du document
le 17 janvier 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-1030Multiples vulnérabilités dans IBM QRadarDe multiples vulnérabilités ont été découvertes dans IBM QRadar. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-1015Multiples vulnérabilités dans les produits IBMRadar Pre-Validation App versions antérieures à 2.0.1
QRadar Pulse App versions antérieures à 2.2.15
QRadar User Behavior Analytics versions antérieures à 4.1.17
Sterling Connect:Direct Web Services versions 6.1.x antérieures à 6.1.0.26
Sterling Connect:Direct Web Services versions 6.2.x antérieures à 6.2.0.25
Sterling Connect:Direct Web Services versions 6.3.x antérieures à 6.3.0.11
VIOS version 3.1 sans le correctif bind_fix27/72bind918.tar
VIOS version 4.1 sans le correctif bind_fix27/73bind918.tar
WebSphere Application Server Liberty sans le correctif APAR PH63533
WebSphere Hybrid Edition sans le correctif APAR PH63533
Les vulnérabilités CVE-2024-47875 et CVE-2024-45801 n'ont pas de correctif pour Sterling Connect:Direct Web Services versions 6.1.x et 6.2.x
Résumé
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité IBM 7176201 du 18 novembre 2024
https://www.ibm.com/support/pages/node/7176201
Bulletin de sécurité IBM 7176205 du 18 nove
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0958Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-45296
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-45590
https://www.cve.org/CVERecord?id=CVE-2024-45590
Référence CVE CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
Référence CVE CVE-2024-46982
https://www.cve.org/CVERecord?id=CVE-2024-46982
Référence CVE CVE-2024-47764
https://www.cve.org/CVERecord?id=CVE-2024-47764
Référence CVE CVE-2024-47874
https://www.cve.org/CVERecord?id=CVE-2024-47874
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2024-5535
https://www.cve.org/CVERecord?id=CVE-2024-5535
Référence CVE CVE-2024-6119
https://www.cve.org/CVERecord?id=CVE-2024-6119
Référence CVE CVE-2024-6232
https://www.cve.org/CVERecord?id=CVE-2024-6232
Référence CVE CVE-2024-6345
https://www.cve.org/CVERecord?id=CVE-2024-6345
Référence CVE CVE-2024-6923
https://www.cve.org/CVERecord?id=CVE-2024-6923
Référence CVE CVE-2024-7592
https://www.cve.org/CVERecord?id=CVE-2024-7592
Référence CVE CVE-2024-8088
https://www.cve.org/CVERecord?id=CVE-2024-8088
Gestion détaillée du document
le 08 novembre 2024
Version initiale
Alertes
A
Official advisory ↗JVN iPedia · Japanese · JVNDB-2024-028481cure53 の DOMPurify におけるクロスサイトスクリプティングの脆弱性cure53 の DOMPurify には、クロスサイトスクリプティングの脆弱性が存在します。
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0382Kwetsbaarheden verholpen in Siemens productenDOMPurify has addressed a nesting-based mXSS vulnerability in versions 2.5.0 and 3.1.3, while HPE Private Cloud AI has identified remote exploit vulnerabilities.
Official advisory ↗