VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202104-1941 CVE-2021-27460 Rockwell Automation  Made  FactoryTalk AssetCentre  Multiple vulnerabilities in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk AssetCentre main server and all agent machines. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets
VAR-202104-1938 CVE-2021-27470 Rockwell Automation  Made  FactoryTalk AssetCentre  Multiple vulnerabilities in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets. Provides centralized tools for securing, managing, versioning, tracking and reporting automation-related asset information across the plant FactoryTalk AssetCentre verifies serialized data A security vulnerability exists that allows remote, unauthenticated attackers to The center executes arbitrary commands
VAR-202104-1942 CVE-2021-27476 Rockwell Automation  Made  FactoryTalk AssetCentre  Multiple vulnerabilities in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets
VAR-202104-1943 CVE-2021-27474 Rockwell Automation  Made  FactoryTalk AssetCentre  Multiple vulnerabilities in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets. Provides centralized tools to secure, manage, version control, track and report automation-related asset information across the factory FactoryTalk AssetCentre has a security vulnerability that stems from not properly restricting all functions related to IIS Remote Services Attackers This vulnerability could be exploited to modify sensitive data in FactoryTalk Asset Center
VAR-202104-1937 CVE-2021-27462 Rockwell Automation  Made  FactoryTalk AssetCentre  Multiple vulnerabilities in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets
VAR-202104-1945 CVE-2021-27468 Rockwell Automation  Made  FactoryTalk AssetCentre  Multiple vulnerabilities in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets. Rockwell Automation FactoryTalk AssetCentre has a SQL injection vulnerability. Provides a centralized tool for securing, managing, versioning, tracking and reporting automation-related asset information across a factory
VAR-202104-1944 CVE-2021-27472 Rockwell Automation FactoryTalk AssetCentre SQL Injection Vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets. Rockwell Automation FactoryTalk AssetCentre has a SQL injection vulnerability
VAR-202104-1940 CVE-2021-27464 Rockwell Automation  Made  FactoryTalk AssetCentre  Multiple vulnerabilities in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets. Rockwell Automation FactoryTalk AssetCentre has a SQL injection vulnerability
VAR-202104-1920 CVE-2020-9146 Huawei  Vulnerability regarding lack of release of resources after valid lifetime on smartphones CVSS V2: 1.9
CVSS V3: 5.5
Severity: MEDIUM
A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to cause memory leakage and doS attacks by carefully constructing attack scenarios. Huawei Smartphones contain a vulnerability regarding the lack of resource release after a valid lifetime.Denial of service (DoS) It may be put into a state. Huawei Emui is an Android-based mobile operating system developed by China's Huawei (Huawei)
VAR-202104-1919 CVE-2020-9147 Huawei  Classic buffer overflow vulnerability in smartphones CVSS V2: 4.4
CVSS V3: 7.8
Severity: HIGH
A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read. Huawei A classic buffer overflow vulnerability exists in smartphones.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Huawei Emui is an Android-based mobile operating system developed by China's Huawei (Huawei)
VAR-202104-1918 CVE-2020-9148 Huawei  Vulnerability in smartphones CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
An application bypass mechanism vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to delete user SMS messages. Huawei There are unspecified vulnerabilities in smartphones.Information may be tampered with
VAR-202104-1917 CVE-2020-9149 Huawei  Vulnerability in smartphones CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
An application error verification vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to modify and delete user SMS messages. Huawei There are unspecified vulnerabilities in smartphones.Information may be tampered with
VAR-202104-1628 CVE-2021-29083 Synology DiskStation Manager  In  OS  Command injection vulnerability CVSS V2: 9.0
CVSS V3: 7.2
Severity: HIGH
Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter. Synology DiskStation Manager (DSM) Has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Synology DiskStation Manager (DSM) is an operating system for network storage servers (NAS) developed by Synology, Taiwan. The operating system can manage data, documents, photos, music and other information
VAR-202104-1582 CVE-2021-26581 HPE Superdome Flex server  Vulnerability in CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following software update to resolve the vulnerability in HPE Superdome Flex Server: Superdome Flex Server Firmware 3.30.142 or later
VAR-202103-1816 No CVE (0Day) D-Link DIR-882 HNAP Stack-based Buffer Overflow Remote Code Execution Vulnerability CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-882 routers. Authentication is not required to exploit this vulnerability.The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.
VAR-202104-0334 CVE-2021-22876 curl  Information Disclosure Vulnerability CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. curl Contains an information disclosure vulnerability.Information may be obtained. This could lead to exposure of the credentials to the server to which requests were redirected. (CVE-2021-22876) A vulnerability was found in curl where a flaw in the option parser for sending NEW_ENV variables libcurl can pass uninitialized data from a stack-based buffer to the server. This issue leads to potentially revealing sensitive internal information to the server using a clear-text network protocol. The highest threat from this vulnerability is to confidentiality. (CVE-2021-22898). Bugs fixed (https://bugzilla.redhat.com/): 2030932 - CVE-2021-44228 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value 5. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. Bugs fixed (https://bugzilla.redhat.com/): 1941964 - CVE-2021-22876 curl: Leak of authentication credentials in URL via automatic Referer 1947493 - Why there is a difference between curl --head output on the RHEL7 and RHEL8. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 security update Advisory ID: RHSA-2021:2472-01 Product: Red Hat JBoss Core Services Advisory URL: https://access.redhat.com/errata/RHSA-2021:2472 Issue date: 2021-06-17 CVE Names: CVE-2020-8169 CVE-2020-8284 CVE-2020-8285 CVE-2020-8286 CVE-2021-22876 CVE-2021-22890 CVE-2021-22901 CVE-2021-31618 ===================================================================== 1. Summary: Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss Core Services on RHEL 7 Server - noarch, ppc64, x86_64 Red Hat JBoss Core Services on RHEL 8 - noarch, x86_64 3. Description: This release adds the new Apache HTTP Server 2.4.37 Service Pack 8 packages that are part of the JBoss Core Services offering. This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 7 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release. Security Fix(es): * curl: Use-after-free in TLS session handling when using OpenSSL TLS backend (CVE-2021-22901) * httpd: NULL pointer dereference on specially crafted HTTP/2 request (CVE-2021-31618) * libcurl: partial password leak over DNS on HTTP redirect (CVE-2020-8169) * curl: FTP PASV command response can cause curl to connect to arbitrary host (CVE-2020-8284) * curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used (CVE-2020-8285) * curl: Inferior OCSP verification (CVE-2020-8286) * curl: Leak of authentication credentials in URL via automatic Referer (CVE-2021-22876) * curl: TLS 1.3 session ticket mix-up with HTTPS proxy host (CVE-2021-22890) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Applications using the APR libraries, such as httpd, must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1847916 - CVE-2020-8169 libcurl: partial password leak over DNS on HTTP redirect 1902667 - CVE-2020-8284 curl: FTP PASV command response can cause curl to connect to arbitrary host 1902687 - CVE-2020-8285 curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used 1906096 - CVE-2020-8286 curl: Inferior OCSP verification 1941964 - CVE-2021-22876 curl: Leak of authentication credentials in URL via automatic Referer 1941965 - CVE-2021-22890 curl: TLS 1.3 session ticket mix-up with HTTPS proxy host 1963146 - CVE-2021-22901 curl: Use-after-free in TLS session handling when using OpenSSL TLS backend 1968013 - CVE-2021-31618 httpd: NULL pointer dereference on specially crafted HTTP/2 request 6. Package List: Red Hat JBoss Core Services on RHEL 7 Server: Source: jbcs-httpd24-1-18.jbcs.el7.src.rpm jbcs-httpd24-apr-1.6.3-105.jbcs.el7.src.rpm jbcs-httpd24-apr-util-1.6.1-82.jbcs.el7.src.rpm jbcs-httpd24-curl-7.77.0-2.jbcs.el7.src.rpm jbcs-httpd24-httpd-2.4.37-74.jbcs.el7.src.rpm jbcs-httpd24-jansson-2.11-55.jbcs.el7.src.rpm jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.jbcs.el7.src.rpm jbcs-httpd24-mod_http2-1.15.7-17.jbcs.el7.src.rpm jbcs-httpd24-mod_jk-1.2.48-16.redhat_1.jbcs.el7.src.rpm jbcs-httpd24-mod_md-2.0.8-36.jbcs.el7.src.rpm jbcs-httpd24-mod_security-2.9.2-63.GA.jbcs.el7.src.rpm noarch: jbcs-httpd24-httpd-manual-2.4.37-74.jbcs.el7.noarch.rpm ppc64: jbcs-httpd24-1-18.jbcs.el7.ppc64.rpm jbcs-httpd24-curl-7.77.0-2.jbcs.el7.ppc64.rpm jbcs-httpd24-curl-debuginfo-7.77.0-2.jbcs.el7.ppc64.rpm jbcs-httpd24-jansson-2.11-55.jbcs.el7.ppc64.rpm jbcs-httpd24-jansson-debuginfo-2.11-55.jbcs.el7.ppc64.rpm jbcs-httpd24-jansson-devel-2.11-55.jbcs.el7.ppc64.rpm jbcs-httpd24-libcurl-7.77.0-2.jbcs.el7.ppc64.rpm jbcs-httpd24-libcurl-devel-7.77.0-2.jbcs.el7.ppc64.rpm jbcs-httpd24-mod_http2-1.15.7-17.jbcs.el7.ppc64.rpm jbcs-httpd24-mod_http2-debuginfo-1.15.7-17.jbcs.el7.ppc64.rpm jbcs-httpd24-mod_md-2.0.8-36.jbcs.el7.ppc64.rpm jbcs-httpd24-mod_md-debuginfo-2.0.8-36.jbcs.el7.ppc64.rpm jbcs-httpd24-runtime-1-18.jbcs.el7.ppc64.rpm x86_64: jbcs-httpd24-1-18.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-1.6.3-105.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-debuginfo-1.6.3-105.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-devel-1.6.3-105.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-debuginfo-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-devel-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-ldap-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-mysql-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-nss-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-odbc-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-openssl-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-pgsql-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-sqlite-1.6.1-82.jbcs.el7.x86_64.rpm jbcs-httpd24-curl-7.77.0-2.jbcs.el7.x86_64.rpm jbcs-httpd24-curl-debuginfo-7.77.0-2.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-debuginfo-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-devel-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-selinux-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-tools-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-jansson-2.11-55.jbcs.el7.x86_64.rpm jbcs-httpd24-jansson-debuginfo-2.11-55.jbcs.el7.x86_64.rpm jbcs-httpd24-jansson-devel-2.11-55.jbcs.el7.x86_64.rpm jbcs-httpd24-libcurl-7.77.0-2.jbcs.el7.x86_64.rpm jbcs-httpd24-libcurl-devel-7.77.0-2.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_cluster-native-debuginfo-1.3.16-5.Final_redhat_2.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_http2-1.15.7-17.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_http2-debuginfo-1.15.7-17.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_jk-ap24-1.2.48-16.redhat_1.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_jk-debuginfo-1.2.48-16.redhat_1.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_jk-manual-1.2.48-16.redhat_1.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_ldap-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_md-2.0.8-36.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_md-debuginfo-2.0.8-36.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_proxy_html-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_security-2.9.2-63.GA.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_security-debuginfo-2.9.2-63.GA.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_session-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_ssl-2.4.37-74.jbcs.el7.x86_64.rpm jbcs-httpd24-runtime-1-18.jbcs.el7.x86_64.rpm Red Hat JBoss Core Services on RHEL 8: Source: jbcs-httpd24-1-18.el8jbcs.src.rpm jbcs-httpd24-apr-1.6.3-105.el8jbcs.src.rpm jbcs-httpd24-apr-util-1.6.1-82.el8jbcs.src.rpm jbcs-httpd24-brotli-1.0.6-40.el8jbcs.src.rpm jbcs-httpd24-curl-7.77.0-2.el8jbcs.src.rpm jbcs-httpd24-httpd-2.4.37-74.el8jbcs.src.rpm jbcs-httpd24-jansson-2.11-55.el8jbcs.src.rpm jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.el8jbcs.src.rpm jbcs-httpd24-mod_http2-1.15.7-17.el8jbcs.src.rpm jbcs-httpd24-mod_jk-1.2.48-16.redhat_1.el8jbcs.src.rpm jbcs-httpd24-mod_md-2.0.8-36.el8jbcs.src.rpm jbcs-httpd24-mod_security-2.9.2-63.GA.el8jbcs.src.rpm jbcs-httpd24-nghttp2-1.39.2-37.el8jbcs.src.rpm jbcs-httpd24-openssl-1.1.1g-6.el8jbcs.src.rpm jbcs-httpd24-openssl-chil-1.0.0-5.el8jbcs.src.rpm jbcs-httpd24-openssl-pkcs11-0.4.10-20.el8jbcs.src.rpm noarch: jbcs-httpd24-httpd-manual-2.4.37-74.el8jbcs.noarch.rpm x86_64: jbcs-httpd24-1-18.el8jbcs.x86_64.rpm jbcs-httpd24-apr-1.6.3-105.el8jbcs.x86_64.rpm jbcs-httpd24-apr-debuginfo-1.6.3-105.el8jbcs.x86_64.rpm jbcs-httpd24-apr-devel-1.6.3-105.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-devel-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-ldap-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-ldap-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-mysql-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-mysql-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-nss-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-nss-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-odbc-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-odbc-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-openssl-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-openssl-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-pgsql-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-pgsql-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-sqlite-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-sqlite-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm jbcs-httpd24-brotli-1.0.6-40.el8jbcs.x86_64.rpm jbcs-httpd24-brotli-debuginfo-1.0.6-40.el8jbcs.x86_64.rpm jbcs-httpd24-brotli-devel-1.0.6-40.el8jbcs.x86_64.rpm jbcs-httpd24-curl-7.77.0-2.el8jbcs.x86_64.rpm jbcs-httpd24-curl-debuginfo-7.77.0-2.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-devel-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-selinux-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-tools-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-tools-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-jansson-2.11-55.el8jbcs.x86_64.rpm jbcs-httpd24-jansson-debuginfo-2.11-55.el8jbcs.x86_64.rpm jbcs-httpd24-jansson-devel-2.11-55.el8jbcs.x86_64.rpm jbcs-httpd24-libcurl-7.77.0-2.el8jbcs.x86_64.rpm jbcs-httpd24-libcurl-debuginfo-7.77.0-2.el8jbcs.x86_64.rpm jbcs-httpd24-libcurl-devel-7.77.0-2.el8jbcs.x86_64.rpm jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.el8jbcs.x86_64.rpm jbcs-httpd24-mod_cluster-native-debuginfo-1.3.16-5.Final_redhat_2.el8jbcs.x86_64.rpm jbcs-httpd24-mod_http2-1.15.7-17.el8jbcs.x86_64.rpm jbcs-httpd24-mod_http2-debuginfo-1.15.7-17.el8jbcs.x86_64.rpm jbcs-httpd24-mod_jk-ap24-1.2.48-16.redhat_1.el8jbcs.x86_64.rpm jbcs-httpd24-mod_jk-ap24-debuginfo-1.2.48-16.redhat_1.el8jbcs.x86_64.rpm jbcs-httpd24-mod_jk-manual-1.2.48-16.redhat_1.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ldap-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ldap-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-mod_md-2.0.8-36.el8jbcs.x86_64.rpm jbcs-httpd24-mod_md-debuginfo-2.0.8-36.el8jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_html-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_html-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-mod_security-2.9.2-63.GA.el8jbcs.x86_64.rpm jbcs-httpd24-mod_security-debuginfo-2.9.2-63.GA.el8jbcs.x86_64.rpm jbcs-httpd24-mod_session-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-mod_session-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ssl-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ssl-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm jbcs-httpd24-nghttp2-1.39.2-37.el8jbcs.x86_64.rpm jbcs-httpd24-nghttp2-debuginfo-1.39.2-37.el8jbcs.x86_64.rpm jbcs-httpd24-nghttp2-devel-1.39.2-37.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-1.1.1g-6.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-chil-1.0.0-5.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-chil-debuginfo-1.0.0-5.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-debuginfo-1.1.1g-6.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-devel-1.1.1g-6.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-libs-1.1.1g-6.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-libs-debuginfo-1.1.1g-6.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-perl-1.1.1g-6.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-pkcs11-0.4.10-20.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-pkcs11-debuginfo-0.4.10-20.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-static-1.1.1g-6.el8jbcs.x86_64.rpm jbcs-httpd24-runtime-1-18.el8jbcs.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-8169 https://access.redhat.com/security/cve/CVE-2020-8284 https://access.redhat.com/security/cve/CVE-2020-8285 https://access.redhat.com/security/cve/CVE-2020-8286 https://access.redhat.com/security/cve/CVE-2021-22876 https://access.redhat.com/security/cve/CVE-2021-22890 https://access.redhat.com/security/cve/CVE-2021-22901 https://access.redhat.com/security/cve/CVE-2021-31618 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYMs2wNzjgjWX9erEAQiuqA//Wj88udaE82j3T1g70vO9Zf9s0Ym+xAWi SmIBQfiNIh9WRy9Jp6DqIxPtG7HQ+++VwXU2lx9LjXuicsQnmKRjdQtvYtqbCzbq uOrxFeLSK1AeI0ic9wo5a7JHxyzcg9yTxCIw8QtTzqpJjJHWTBK/xtiYp9V6A2xF NaXdlAyCRfje+0+EygZGBdX5UD6cr8vTLPtVmp2t+NfvyB7YQaHwSMi7ZzKvmN61 ZLj5++qEWde9k8zovupYAAe9suIwzaL4bdgbwdSyFYH/CDA1E9oyo22inzO4iaka ixwuhI8rnToaVLNyn7p/Ra585stBQ1GUE27dJBvlabYa35gdoVVy+e0mRsQ/pS3R vE48A9yOLhSaof8l2ZDQRuhr6KBFFEvdln7TcftIdQG7/iTVo0R03AxigGGn1bSv HQ911R6wcPAU300VfeIo5btkbJCPBHoovYCBJYBVlF5wjQ7RCWlr9VrX/wqMun68 8IrfPX8j4PIwUvxPygqIFUjg0xZHWiVN8H6tNeJKD8kHfv/4vCIOo9ZWxFI5VFV/ /2pqWtm5tnf3yfqFn8Z6OrkaQFR8q0jg0d2VLS4AmKC4joLTXvBZVKLEfLF+HGlO QnEYJ2EhDWHSU+ZViI/anzTRnN5tBxNxqsPn7rfTXLmxxwkUH9hgaCzVMG5MXYOZ lIrXPlR2tmY= =6HuS -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce . Description: Red Hat Advanced Cluster Management for Kubernetes 2.2.10 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console — with security policy built in. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.2/html/release_notes/ Security fixes: * CVE-2021-3795 semver-regex: inefficient regular expression complexity * CVE-2021-23440 nodejs-set-value: type confusion allows bypass of CVE-2019-10747 Related bugs: * RHACM 2.2.10 images (Bugzilla #2013652) 3. Bugs fixed (https://bugzilla.redhat.com/): 2004944 - CVE-2021-23440 nodejs-set-value: type confusion allows bypass of CVE-2019-10747 2006009 - CVE-2021-3795 semver-regex: inefficient regular expression complexity 2013652 - RHACM 2.2.10 images 5. Red Hat OpenShift Container Storage is highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Container Storage provides a multicloud data management service with an S3 compatible API. Bug Fix(es): * Previously, when the namespace store target was deleted, no alert was sent to the namespace bucket because of an issue in calculating the namespace bucket health. With this update, the issue in calculating the namespace bucket health is fixed and alerts are triggered as expected. (BZ#1993873) * Previously, the Multicloud Object Gateway (MCG) components performed slowly and there was a lot of pressure on the MCG components due to non-optimized database queries. With this update the non-optimized database queries are fixed which reduces the compute resources and time taken for queries. Bugs fixed (https://bugzilla.redhat.com/): 1993873 - [4.8.z clone] Alert NooBaaNamespaceBucketErrorState is not triggered when namespacestore's target bucket is deleted 2006958 - CVE-2020-26301 nodejs-ssh2: Command injection by calling vulnerable method with untrusted input 5. Bugs fixed (https://bugzilla.redhat.com/): 1992006 - CVE-2021-29923 golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet 2006044 - CVE-2021-39293 golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196) 2012887 - CVE-2021-38297 golang: Command-line arguments may overwrite global data 2024838 - Release of OpenShift Serverless Eventing 1.20.0 2024839 - Release of OpenShift Serverless Serving 1.20.0 5
VAR-202103-1352 CVE-2021-26943 ASUS UX360CA BIOS  Vulnerability in CVSS V2: 7.2
CVSS V3: 8.2
Severity: HIGH
The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary physical memory locations, including SMRAM, and execute arbitrary code in the SMM (issue 3 of 3). ASUS UX360CA BIOS Contains an unspecified vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Asus UX360CA BIOS through 303 is a notebook computer from Asus, Japan. UX360CA BIOS through 303 on ASUS has a security vulnerability
VAR-202104-0435 CVE-2021-22327 Huawei P30 memory write vulnerability CVSS V2: 4.3
CVSS V3: 6.5
Severity: MEDIUM
There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input files, successful exploit could cause certain service abnormal. Affected product versions include:HUAWEI P30 versions 10.0.0.186(C10E7R5P1), 10.0.0.186(C461E4R3P1), 10.0.0.188(C00E85R2P11), 10.0.0.188(C01E88R2P11),10.0.0.188(C605E19R1P3), 10.0.0.190(C185E4R7P1), 10.0.0.190(C431E22R2P5), 10.0.0.190(C432E22R2P5),10.0.0.190(C605E19R1P3), 10.0.0.190(C636E4R3P4), 10.0.0.192(C635E3R2P4). Huawei P30 is a smart phone of China's Huawei (Huawei) company. The vulnerability stems from the program's failure to properly validate the input file. Attackers use this vulnerability to cause abnormal program services
VAR-202104-0437 CVE-2021-22330 Huawei P30 memory write out-of-bounds vulnerability CVSS V2: 3.3
CVSS V3: 6.5
Severity: MEDIUM
There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the service to be abnormal. Huawei P30 is a smart phone of China's Huawei (Huawei) company. Attackers exploiting this vulnerability may cause a denial of service
VAR-202103-1167 CVE-2021-26810 D-link DIR-816 A2  Code injection vulnerabilities CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter. D-link DIR-816 A2 Contains a code injection vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. D-link DIR-816 A2 is a wireless AC750 dual-band router