Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-26979PUBLISHED: 2022-08-06Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
CVE-2022-27944PUBLISHED: 2022-08-06Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.
CVE-2022-2688PUBLISHED: 2022-08-06
A vulnerability was found in SourceCodester Expense Management System. It has been rated as critical. This issue affects the function fetch_report_credit of the file report.php of the component POST Parameter Handler. The manipulation of the argument from/to leads to sql injection. The attack may be...
CVE-2022-2689PUBLISHED: 2022-08-06
A vulnerability classified as problematic has been found in SourceCodester Wedding Hall Booking System. Affected is an unknown function of the file /whbs/?page=contact_us of the component Contact Page. The manipulation of the argument Message leads to cross site scripting. It is possible to launch t...
CVE-2022-2690PUBLISHED: 2022-08-06
A vulnerability classified as problematic was found in SourceCodester Wedding Hall Booking System. Affected by this vulnerability is an unknown functionality of the file /whbs/?page=my_bookings of the component Booking Form. The manipulation of the argument Remarks leads to cross site scripting. The...
User Rank: Author
10/20/2014 | 3:29:06 PM
First, there's nothing you can do about it. High speed software development is happening and it's very unlikely that security can make it stop (not that you'd want to). If you try you will make yourself extremely unpopular and get marginalized. Ultimately, you'll end up hurting security by getting yourself cut out of the loop.
Second, these movements are a *massive* opportunity to do security better. These efforts are establishing the infrastructure necessary to do security at high-speed. Security folks just need to learn about the tools being used for software development -- tools like Jenkins, Sonar, JIRA, Puppet, and others are easy to leverage to do realtime application security at scale.
Try the free Contrast for Eclipse with your Java developers, and see what a huge difference *fast* can make. It really does change everything.
--Jeff