Tech Center Security Management

Dark Reading's Security Management Tech Center is your destination for news and information surrounding the administrative and professional tasks that information security professionals must perform every day. Written for career security pros, The Security Management Tech Center is designed to provide insight on security career choices, staffing and budgetary issues, and day-to-day administrative tasks such as security reporting and architecture planning.

Featured Commentary

News

More Stories

By The Numbers

Information Security Salaries Split

Infosec managers saw their salaries rise, while staffers felt a slight dip in 2013.

Information Security Salaries Split

Source: InformationWeek 2013 IT Salary Survey

Commentary

Around the Web

Sign up for the Dark Reading Daily email newsletter

*Required field

Privacy Statement

Dark Reading Digital Magazine

In This Issue

  • Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
  • Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
  • BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Download Now

Bugs

Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database

  • CVE-2013-2969

    Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.

  • CVE-2013-2968

    An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.

  • CVE-2013-4622

    The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.

  • CVE-2013-0484

    The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.

  • CVE-2013-3744 (jre, jdk)

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.