Multiple vulnerabilities have been published by IBM in its webMethods Integration Server which cloud allow attackers to execute arbitrary commands on affected systems.
Those published vulnerabilities have been identified in version 10.15 of the software which pose a severe risk for the organizations to integrate and API management.
By infosecbulletin
/ Saturday , October 5 2024
National Attack Surface (NAS) report for the first half of 2024 reveals that 56.6% of cyberattacks in Bangladesh targeted educational...
Read More
By infosecbulletin
/ Saturday , October 5 2024
A new ransomware campaign is targeting individuals and organizations in the UK and US. The "Prince Ransomware" attack uses a...
Read More
By infosecbulletin
/ Friday , October 4 2024
CISA has issued an urgent alert about critical vulnerabilities being exploited in Synacor’s Zimbra Collaboration and Ivanti’s Endpoint Manager (EPM)....
Read More
By infosecbulletin
/ Friday , October 4 2024
ISACA 2024 survey report reveals that 66% of cybersecurity professionals find their jobs more stressful now than five years ago....
Read More
By infosecbulletin
/ Friday , October 4 2024
A recent study by ISACA shows that almost two-thirds of cybersecurity professionals report increasing job stress. The 2024 State of...
Read More
By infosecbulletin
/ Friday , October 4 2024
In September, cybersecurity experts discovered 31 new ransomware variants that threaten individuals and businesses. These programs encrypt valuable data, making...
Read More
By infosecbulletin
/ Thursday , October 3 2024
New guidance on ransomware, released during this week's International Counter Ransomware Initiative (CRI) meeting, encourages victims to report attacks to...
Read More
By infosecbulletin
/ Thursday , October 3 2024
Over 14 new security flaws have been found in DrayTek routers for homes and businesses, which could allow attackers to...
Read More
By infosecbulletin
/ Wednesday , October 2 2024
Hackers are exploiting a recently revealed RCE vulnerability in Zimbra email servers that can be activated by sending specially crafted...
Read More
By infosecbulletin
/ Wednesday , October 2 2024
CISA warns of two serious vulnerabilities in Optigo Networks ONS-S8 Aggregation Switches, which could allow authentication bypass and remote code...
Read More
CVE-2024-45076 has been assigned as high severity scoring CVSS base score of 9.9 which allows an authenticated user to upload and execute arbitrary files on the underlying operating system.
The potential for exploitation is high, given the low complexity required to carry out an attack, and the lack of user interaction needed. The impact on confidentiality, integrity, and availability is rated as high, making it imperative for organizations to address this issue urgently.
CVE-2024-45075 which has a CVSS base score of 8.8 involves privilege escalation which allows An authenticated user could exploit this flaw to create scheduler tasks that escalate their privileges to an administrator level due to missing authentication checks.
CVE-2024-45074 which allows directory traversal attacks to enable an attacker viewing arbitrary files on the system, has a CVSS base score of 6.5 still poses a significant threat by potentially exposing sensitive information.
IBM released Corefix 14 for the Integration Server to install using the Update Manager to mitigate these vulnerabilities. No workarounds or mitigations are available.
These vulnerabilities highlight the ongoing challenges in securing complex integration platforms, which cyber attackers increasingly target due to their critical role in enterprise environments.
Organizations are urged to review their security posture and ensure that all systems are updated to protect against the potential exploitation of these vulnerabilities.