Cisco Patches Critical Flaw After PoC Exploit Code Release

A critical path-traversal flaw (CVE-2020-27130) exists in Cisco Security Manager that lays bare sensitive information to remote, unauthenticated attackers.

Threatpost - English - Global - threatpost.com
IBM Spectrum Protect Plus Security Open to RCE - Two bugs (CVE-2020-4703 and CVE-2020-4711) in IBM's Spectrum Protect Plus data-storage protection ... https://threatpost.com/ibm-flaws-spectrum-protect-plus/159268/ #arbitrarycodeexecution #remotecodeexecution #spectrumprotectplus #pathtraversalflaw #highseverityflaw #vulnerabilities #cve-2020-4470 #cve-2020-4703 #cve-2020-4711 #ibmspectrum #patch #ibm
IBM Spectrum Protect Plus Security Open to RCE

Two high-severity bugs (CVE-2020-4703 and CVE-2020-4711) in IBM's Spectrum Protect Plus data-storage protection solution could enable remote code execution.

Threatpost - English - Global - threatpost.com
Researchers Warn of High-Severity Dell PowerEdge Server Flaw - A path traversal vulnerability in the iDRAC technology can allow remote attackers to take over con... more: https://threatpost.com/researchers-warn-of-high-severity-dell-poweredge-server-flaw/157795/ #pathtraversalflaw #vulnerabilities #idractechnology #vulnerability #server #patch #dell
Researchers Warn of High-Severity Dell PowerEdge Server Flaw

A path traversal vulnerability in the iDRAC technology can allow remote attackers to take over control of server operations.

Threatpost - English - Global - threatpost.com
Critical GitLab Flaw Earns Bounty Hunter $20K - A GitLab path traversal flaw could allow attackers to read arbitrary files and remotely execute co... more: https://threatpost.com/critical-gitlab-flaw-bounty-20k/155295/ #securityvulnerability #remotecodeexecution #arbitraryfileread #pathtraversalflaw #vulnerabilities #gitlabbugbounty #williambowling #bountyhunter #bugbounty #hackerone #critical #gitlab #$20 #rce
Critical GitLab Flaw Earns Bounty Hunter $20K

A GitLab path traversal flaw could allow attackers to read arbitrary files and remotely execute code.

Threatpost - English - Global - threatpost.com