HomeSecurityCISA warns of 5 vulnerabilities that are being actively exploited

CISA warns of 5 vulnerabilities that are being actively exploited

The Cybersecurity and Infrastructure Security Administration (CISA) has issued an urgent warning regarding 5 critical vulnerabilities that are actively being exploited.

See also: SolarWinds: Fixes vulnerabilities in Access Rights Manager (ARM)

CISA vulnerabilities

Organizations using products are urged to implement mitigations provided by the vendor or discontinue use if no workarounds are available.

Vulnerabilities, such as the 5 identified by CISA, refer to weak points in a system that can be exploited by malicious actors to gain unauthorized access or cause harm. In technology, vulnerabilities are often associated with software, where the vulnerabilities can lead to attacks through malware, surveillance, or even data theft. Identifying and fixing these vulnerabilities is crucial to ensuring the security and reliability of systems. Organizations must continually invest in research and security upgrades to keep information protected from potential risks.

CVE-2024-27348 – Apache HugeGraph Server Vulnerability

CVE-2024-27348 highlights a critical access control vulnerability in Apache HugeGraph-Server. This flaw allows remote attackers to execute arbitrary code, potentially leading to unauthorized access and control of affected systems.

CVE-2020-0618 – Microsoft SQL Server Reporting Services Vulnerability

Identified as CVE-2020-0618, this vulnerability affects Microsoft SQL Server Reporting Services. It includes a deserialization flaw that authenticated attackers to execute code with the privileges of the Reporting Server service account.

See also: D-Link fixes critical vulnerabilities in WiFi 6 routers

cisa vulnerabilities
CISA warns of 5 critical vulnerabilities

CVE-2019-1069 – Microsoft Windows Task Scheduler Vulnerability

CVE-2019-1069 concerns an elevation of privilege vulnerability in Microsoft Windows Task Scheduler. By exploiting the SetJobFileSecurityByName(), attackers could gain SYSTEM.

CVE-2022-21445 – Oracle JDeveloper Vulnerability

Oracle JDeveloper, part of the Fusion Middleware suite , is affected by CVE-2022-21445 . This remote code execution vulnerability results from a deserialization issue in the ADF Faces component , allowing attackers to remotely execute arbitrary code

CVE-2020-14644 – Oracle WebLogic Server Vulnerability

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CVE-2020-14644 affects Oracle WebLogic Server, another component of the Fusion Middleware suite. Unauthenticated attackers with network access via T3 or IIOP could exploit this deserialization vulnerability, allowing remote code execution.

See also: Citrix warns of vulnerabilities in Workspace for Windows

CISA's warning highlights the critical nature of these 5 vulnerabilities and the need for immediate action.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS