Published Description
25-09-2018 17:29:00
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
25-09-2018 17:29:00
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
25-09-2018 11:29:01
IBM DataPower Gateway -, -, -, -, -, and - as well as IBM DataPower Gateway CD - echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890.
25-09-2018 11:29:01
IBM DataPower Gateway -, -, -, -, -, and - as well as IBM DataPower Gateway CD - are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 144950.
25-09-2018 11:29:00
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.