CVE-2024-20738 – Adobe FrameMaker Publishing Server Authentication Bypass Vulnerability | CVE-2023-44324 bypass
https://notcve.org/view.php?id=CVE-2024-20738
Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction. Las versiones 2022.1 y anteriores de Adobe Framemaker se ven afectadas por una vulnerabilidad de autenticación incorrecta que podría provocar la omisión de una función de seguridad. Un atacante podría aprovechar esta vulnerabilidad para eludir los mecanismos de autenticación y obtener acceso no autorizado. • https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-10.html • CWE-287: Improper Authentication •
CVE-2024-0056 – Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2024-0056
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability Vulnerabilidad de omisión de característica de seguridad del proveedor de datos SQL de Microsoft.Data.SqlClient y System.Data.SqlClient A vulnerability was found in the .NET Framework. This vulnerability exists in the Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data provider where an attackercan perform an AiTM (adversary-in-the-middle) attack between the SQL client and the SQL server. This may allow the attacker to steal authentication credentials intended for the database server, even if the connection is established over an encrypted channel like TLS. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-0056 https://access.redhat.com/security/cve/CVE-2024-0056 https://bugzilla.redhat.com/show_bug.cgi?id=2255384 • CWE-319: Cleartext Transmission of Sensitive Information CWE-420: Unprotected Alternate Channel •
CVE-2023-44324 – ZDI-CAN-21344: Adobe FrameMaker Publishing Server Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2023-44324
Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password. Exploitation of this issue does not require user interaction. Las versiones 2022 y anteriores de Adobe FrameMaker se ven afectadas por una vulnerabilidad de autenticación incorrecta que podría provocar la omisión de una función de seguridad. Un atacante no autenticado puede aprovechar esta vulnerabilidad para acceder a la API y filtrar la contraseña de administrador predeterminada. • https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb23-58.html • CWE-287: Improper Authentication •
CVE-2022-29125 – Windows Push Notifications Apps Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2022-29125
Windows Push Notifications Apps Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows Push Notifications Apps • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-29125 •
CVE-2022-29122 – Windows Clustered Shared Volume Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2022-29122
Windows Clustered Shared Volume Information Disclosure Vulnerability Una vulnerabilidad de Divulgación de Información de Windows Clustered Shared Volume. Este ID de CVE es diferente de CVE-2022-29120, CVE-2022-29123, CVE-2022-29134 • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-29122 •