Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Steven Thompson

#17653of 53,633
15.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2019-17004
5.9
2019-05-29
Ibm · Ibm Qradar Siem · CVE-2019-4264
**Name of the Vulnerable Software and Affected Versions** IBM QRadar SIEM version 7.2.8 **Description** The issue allows an attacker to obtain sensitive information by spoofing a trusted entity using man-in-the-middle techniques due to not validating or incorrectly validating a certificate. **Recommendations** For IBM QRadar SIEM version 7.2.8, consider implementing certificate validation to prevent man-in-the-middle attacks. As a temporary workaround, restrict access to trusted entities to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-18505
9.3
2018-07-11
Microsoft · Skype For Business · CVE-2018-8238
**Name of the Vulnerable Software and Affected Versions** Skype for Business (affected versions not specified) Microsoft Lync (affected versions not specified) **Description** A security feature bypass issue exists due to improper parsing of UNC path links shared via messages. This issue affects Skype and Microsoft Lync products. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.