-
About CVE-2023-46129: If your payment system is designed like this technique. You should remain alert! (2nd Nov 2023)
Preface: The payment systems based on a distributed architecture will be enhanced efficient and scalable. Therefore, distributed ledger technology (DLT) will become a trend in future. The DLT Pilot Regime defines “tokenization of financial instruments” as a process that involves the conversion of traditional financial asset classes into digital tokens that can be stored, transferred…
-
CVE-2023-5056: A design weakness was found in the Skupper operator causes unauthorized viewing of information outside of the user’s purview.(1st Nov 2023)
Preface: Government agencies and companies in emerging tech, finance, healthcare, and other industries use Red Hat® products and services. OpenShift gives organizations the ability to build, deploy, and scale applications faster both on-premises and in the cloud. It also protects your development infrastructure at scale with enterprise-grade security. Background: Skupper is a layer 7 service…
-
CVE-2023-21372: Google Android design flaw, component Libdexfile triggers an out-of-bounds vulnerability. (31st Oct 2023)
Preface: Many users agree that learning Apex is simpler than learning Java because there is less syntax. Background: Apex is a proprietary language developed by Salesforce.com. It is a strongly typed, object-oriented programming language that allows developers to execute flow and transaction control statements on the Force.com platform server in conjunction with calls to the…
-
Remedy of CVE-2023-46862: Kernel (io_uring/fdinfo[.]c) enhancement: lock SQ thread while retrieving thread cpu/pid (30th Oct 2023)
Preface: Quick comparison of Windows (IoRing) and Linux (io_uring): Windows: The kernel fully initializes the new ring, including the creation of both queues and creating a shared view in the application’s user-mode address space, using an MDL (memory descriptor list). Linux: In the Linux io_uring implementation, the system creates the requested ring and the queues…
-
Don’t take it lightly CVE-2023-46753: Regarding the BGP protocol using FRRouting (26-10-2023)
Preface: Microsoft has been a mainstay of the computer systems world for more than four decades. At the same time, it also promotes the development of the Internet and other technologies. About fifteen years ago, virtual machines led the way, bringing the concept into the business world and successfully fending off mainstream cybersecurity attacks. It…
-
CVE-2023-5044 : Design weakness of ingress-nginx (26th Oct 2023)
Preface: You can configure the nginx ingress controller in various ways. To use the Openstack load balancer Octavia with ssl offloading you will need to configure the ingress controller with the proxy protocol. The alternative would be to use the Openstack service barbican to store your ssl certificate. Which is currently not directly supported by…
-
SUSE Enterprise Linux Server 15: Apart from libvirt framework , how to manages memory in units called pages? (25-10-2023)
Preface: HPE Cray OS Based on standard SUSE Enterprise Linux Server 15. A supercomputer, dubbed Frontier, was developed by HPE Cray. Frontier and HPE Cray OS to run standard Linux applications, but rather enhance it for performance, scale, and reliability. Ref: Frontier is based on the latest HPE Cray EX235a architecture and equipped with AMD…
-
Closer look of CVE-2023-34051: VMware Aria Operations for Logs contains an authentication bypass vulnerability. (24th Oct 2023)
Preface: VMware Aria Operations™ for Logs (formerly VMware vRealize® Log Insight™) analyzes complex log management through dashboards to provide shortest path to identify the problem. Background: What is aria operations for logs? Centralized Log Management VMware Aria Operations for Logs. Manage data at scale with centralized log management, deep operational visibility, and intelligent analytics for…
-
Closer look of CVE-2023-4966 (19-10-2023)
Preface: On October 10, 2023, Citrix released a security advisory regarding a sensitive information disclosure vulnerability (CVE-2023-4966) affecting NetScaler ADC and NetScaler Gateway appliances. Background: Citrix NetScaler improves performance by using HTTP compression and data caching. The workload is shared over multiple servers and networks to ensure that there is not one point of failure…
-
CVE-2023-22089: About Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). (18-10-2023)
Preface: When Oracle releases a security advisory. These vulnerabilities may have occurred months ago, or may be further back. But the technical details published in the CVE are only limited. So, that’s one of the reasons I’m interested in digging into the details. In the spirit of science, everyone dares to assume but careful to…