Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-1883PUBLISHED: 2022-05-25SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.
CVE-2022-21951PUBLISHED: 2022-05-25
A Missing Encryption of Sensitive Data vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is created from an RKE template with the CNI value overridden This issue affects:...
CVE-2022-1815PUBLISHED: 2022-05-25Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
CVE-2022-29405PUBLISHED: 2022-05-25In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
CVE-2022-29349PUBLISHED: 2022-05-25kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
User Rank: Apprentice
12/23/2013 | 6:48:16 PM
Of course all of these activities rarely require the full account info. Generally PCI requires truncation to store transactions but Target may have demonstrated a mitigating factor by encrypting all transactions. Thats why its probably an inside job... someone with access to the necessary decryption information.
Another article I read said the cvv codes were not stolen which meant the stolen accounts are not useful for most on-line purchases.
IMO ... regrdless of this article's title, we don't really know what happened yet.