Autore: Angelo Barbosa

CVE-2023-46589 | Apache Tomcat up to 8.5.95/9.0.82/10.1.15/11.0.0-M10 HTTP Trailer Header request smuggling

A vulnerability was found in Apache Tomcat up to 8.5.95/9.0.82/10.1.15/11.0.0-M10 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Trailer Header Handler. The manipulation leads to http request smuggling. This vulnerability is handled as CVE-2023-46589. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2022-41678 | Apache ActiveMQ up to 5.16.5/5.17.3 deserialization

A vulnerability has been found in Apache ActiveMQ up to 5.16.5/5.17.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest. The manipulation leads to deserialization. This vulnerability is known as CVE-2022-41678. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-6239 | M-Files Server 23.9/23.10/23.11 Configuration permissions

A vulnerability, which was classified as critical, has been found in M-Files Server 23.9/23.10/23.11. This issue affects some unknown processing of the component Configuration Handler. The manipulation leads to preservation of permissions. The identification of this vulnerability is CVE-2023-6239. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più